漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
OpenEMR 8.2.0 OAuth2 Dynamic Client Registration Unauthorized FHIR Access
Vulnerability Description
OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoint that allows unauthenticated attackers to register a malicious client with system-level FHIR scopes by supplying a self-generated RSA keypair via the jwks field. Once an administrator approves the registered client, attackers can use the client_credentials grant with a self-signed JWT assertion to obtain access tokens granting read access to all FHIR resources across all patients in the system.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Vulnerability Type
关键功能的认证机制缺失
Vulnerability Title
OpenEMR 授权问题漏洞
Vulnerability Description
openemr是OpenEMR组织开源的一个支持文档管理与企业应用场景的医疗信息管理平台。 OpenEMR 8.2.0及之前版本存在授权问题漏洞,该漏洞源于OAuth2动态客户端注册端点身份验证不当,可能导致未经身份验证的攻击者通过jwks字段提供自生成的RSA密钥对注册恶意客户端,经管理员批准后获取访问令牌,从而读取系统中所有患者的FHIR资源。
CVSS Information
N/A
Vulnerability Type
N/A