{"id":"CVE-2023-28465","details":"The package-decompression feature in HL7 (Health Level 7) FHIR Core Libraries before 5.6.106 allows attackers to copy arbitrary files to certain directories via directory traversal, if an allowed directory name is a substring of the directory name chosen by the attacker. NOTE: this issue exists because of an incomplete fix for CVE-2023-24057.","aliases":["GHSA-9654-pr4f-gh6m"],"modified":"2026-08-12T03:51:26.039591561Z","published":"2023-12-12T00:00:00Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/28xxx/CVE-2023-28465.json","unresolved_ranges":[{"source":"DESCRIPTION","extracted_events":[{"fixed":"5.6.106"}]}],"cna_assigner":"mitre"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/28xxx/CVE-2023-28465.json"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9654-pr4f-gh6m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-28465"},{"type":"ARTICLE","url":"https://www.smilecdr.com/our-blog"},{"type":"ARTICLE","url":"https://www.smilecdr.com/our-blog/statement-on-cve-2023-24057-smile-digital-health"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/hapifhir/org.hl7.fhir.core","events":[{"introduced":"0"},{"fixed":"d666d0aa809daa980265df6b66552f4b4fdc15a7"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"5.6.106"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:hapifhir:hl7_fhir_core:*:*:*:*:*:*:*:*"}}],"versions":["5.6.105","5.6.104","5.6.103","5.6.102","5.6.101","5.6.100","5.6.97","5.6.99","5.6.98","5.6.92","5.6.96","5.6.88","5.6.91","5.6.90","5.6.89","5.6.87","5.6.86","5.6.85","5.6.84","5.6.80","5.6.79","5.6.78","5.6.77","5.6.76","5.6.75","5.6.74","5.6.72","5.6.71","5.6.70","5.6.69","5.6.68","5.6.67","5.6.66","5.6.65","5.6.64","5.6.63","5.6.62","5.6.61","5.6.56","5.6.54","5.6.53","5.6.52","5.6.50","5.6.48","5.6.47","5.6.46","5.6.45","5.6.44","5.6.43","5.6.42","5.6.29","5.6.28","5.6.27","5.6.26","5.6.25","5.6.24","5.6.23","5.6.22","5.6.20","5.6.21","5.6.19","5.6.18","5.6.17","5.6.15","5.6.9","5.6.7","5.6.6","5.6.4","5.6.3","5.6.1","5.6.0","5.5.15","5.5.14","5.5.13","5.5.12","5.5.11","5.5.10","5.5.9","5.5.8","5.5.7","5.5.6","5.5.4","5.5.3","5.5.1","1.1.67","5.4.12","5.4.10","5.4.9","5.4.8","5.4.7","5.4.6","5.4.5","5.4.4","5.4.3","5.4.2","5.3.14","5.4.1","v5.4.0","5.3.12","5.3.11","5.3.10","5.3.9","5.3.7","5.3.6","5.3.5","5.3.4","5.3.3","5.3.2","5.3.1","v5.3.0","5.1.7","5.1.6","5.1.4","5.1.3","5.1.2","5.1.1","5.0.22","5.0.21","5.0.20","5.0.19","5.0.18","5.0.17","5.0.16","5.0.13","5.0.14","5.0.12","5.0.11","5.0.10","5.0.9","5.0.8","5.0.7"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-28465.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}