REDHAT-BUG-2449841: High severity Hapi FHIR vulnerability
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.0, when setting headers in HTTP requests, the internal HTTP client sends headers first to the host in the initial URL but also, if asked to follow redirects and a 30X HTTP response code is returned, to the host mentioned in URL in the Location: response header value. Sending the same set of headers to subsequent hosts is a problem as this header often contains privacy sensitive information or data that could allow others to impersonate the client's request. This issue has been patched in release 6.9.0. No known workarounds are available.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
HAPI FHIR (Java)to a version that resolves this vulnerability.Fixed in 6.9.0
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2449841?
The severity of REDHAT-BUG-2449841 is classified as high with a score of 7.
How do I fix REDHAT-BUG-2449841?
To fix REDHAT-BUG-2449841, upgrade to Hapi FHIR version 6.9.0 or later.
What are the risks associated with REDHAT-BUG-2449841?
REDHAT-BUG-2449841 poses a risk of sensitive information exposure due to improper handling of HTTP headers.
What software is affected by REDHAT-BUG-2449841?
The software affected by REDHAT-BUG-2449841 is Hapi FHIR, specifically versions prior to 6.9.0.
When was REDHAT-BUG-2449841 published?
REDHAT-BUG-2449841 was published on March 20, 2026.