Skip to main content

Get a free FHIR vulnerability scan, funded by Cantina.

All disclosures

Vulnerability disclosure

SMART patient selection grants access to another patient's documents

GHSA-rm4j-gxwp-qh48

Affected product
OpenEMR
Severity
Medium
Disclosed

Summary

A low-privileged OpenEMR SMART launch user with demographics access could select another patient during authorization and receive a token bound to that patient. The reported test used it to read a clinical note and download a patient document. Affects versions before 8.4.0; fixed in 8.4.0.

Disclosure timeline

Public disclosure

Credits

Cantina · Agent-discovered and human-verified

References