vulnerability
OHIF Viewers DICOM
High
Summary
This advisory details a vulnerability in the OHIF Viewers DICOM framework, specifically versions up to v3.12.0, that allows attackers to steal authenticated user tokens via crafted links. The vulnerability stems from unchecked URL parameters within the DICOMWebProxy and DICOMJSON data sources, which inject the user's OIDC Bearer token into requests. Organizations are advised to upgrade to version 3.12.2 or later and implement specific configuration changes to mitigate the risk.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data