news.mlab.sh
Back to the feed
vulnerability

OHIF Viewers DICOM

High
Summary

This advisory details a vulnerability in the OHIF Viewers DICOM framework, specifically versions up to v3.12.0, that allows attackers to steal authenticated user tokens via crafted links. The vulnerability stems from unchecked URL parameters within the DICOMWebProxy and DICOMJSON data sources, which inject the user's OIDC Bearer token into requests. Organizations are advised to upgrade to version 3.12.2 or later and implement specific configuration changes to mitigate the risk.

Read the full article at CISA Advisories

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.