Description
OpenClinic version 0.8.2 is affected by a missing authentication vulnerability that allows unauthenticated users to access any patient's medical test results, possibly resulting in disclosure of Protected Health Information (PHI) stored in the application, via a direct request for the /tests/ URI.
Published: 2020-12-03
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-21325 OpenClinic version 0.8.2 is affected by a missing authentication vulnerability that allows unauthenticated users to access any patient's medical test results, possibly resulting in disclosure of Protected Health Information (PHI) stored in the application, via a direct request for the /tests/ URI.
History

No history.

Subscriptions

Openclinic Project Openclinic
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T16:47:59.895Z

Reserved: 2020-11-19T00:00:00.000Z

Link: CVE-2020-28937

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-12-03T16:15:12.370

Modified: 2024-11-21T05:23:19.780

Link: CVE-2020-28937

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses