Skip to main content

Get a free FHIR vulnerability scan, funded by Cantina.

All disclosures

Vulnerability disclosure

FHIR document export exposes another patient's clinical summary

GHSA-r79c-4hf6-fgp3

Affected product
OpenEMR
Severity
Medium · CVSS 6.5
Disclosed

Summary

OpenEMR's FHIR $docref endpoint accepted a caller-selected patient after checking only demographics access. A staff user with demographics and document permissions could generate and download another patient's C-CDA clinical summary through Patient Documents. Affects versions before 8.4.0; fixed in 8.4.0.

Disclosure timeline

Public disclosure

Credits

Reported by christos-cantina-security; remediation by kojiromike, as credited in OpenEMR's advisory.

References