Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTY3ZjYtYzhteC00cTJt
Uncontrolled Resource Consumption in JPA Server in HAPI FHIR
JPA Server in HAPI FHIR before 5.4.0 allows a user to deny service (e.g., disable access to the database after the attack stops) via history requests. This occurs because of a SELECT COUNT statement that requires a full index scan, with an accompanying large amount of server resources if there are many simultaneous history requests.
Permalink: https://github.com/advisories/GHSA-67f6-c8mx-4q2mJSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTY3ZjYtYzhteC00cTJt
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: almost 2 years ago
Updated: 4 months ago
CVSS Score: 5.3
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Identifiers: GHSA-67f6-c8mx-4q2m, CVE-2021-32053
References:
- https://nvd.nist.gov/vuln/detail/CVE-2021-32053
- https://github.com/hapifhir/hapi-fhir/issues/2641
- https://github.com/hapifhir/hapi-fhir/pull/2642
- https://hapifhir.io
- https://github.com/advisories/GHSA-67f6-c8mx-4q2m
Affected Packages
maven:ca.uhn.hapi.fhir:hapi-fhir-jpaserver-base
Versions: < 5.4.0Fixed in: 5.4.0