An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities.
This issue has been addressed in the following products: Red Hat build of Apache Camel 4.4.4 for Spring Boot Via RHSA-2024:9806 https://access.redhat.com/errata/RHSA-2024:9806
This issue has been addressed in the following products: Red Hat Build of Apache Camel 4.4 for Quarkus 3.8 Via RHSA-2024:10035 https://access.redhat.com/errata/RHSA-2024:10035