Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2023-31138
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
DHIS2 Core vulnerable to Improper Access Control with PATCH requests
Source: NVD (National Vulnerability Database)
Vulnerability Description
DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.36 branch and prior to versions 2.37.9.1, 2.38.3.1, and 2.39.1.2, using object model traversal in the payload of a PATCH request, authenticated users with write access to an object may be able to modify related objects that they should not have access to. DHIS2 implementers should upgrade to a supported version of DHIS2 to receive a patch: 2.37.9.1, 2.38.3.1, or 2.39.1.2. It is possible to work around this issue by blocking all PATCH requests on a reverse proxy, but this may cause some issues with the functionality of built-in applications using legacy PATCH requests.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Source: NVD (National Vulnerability Database)
Vulnerability Type
访问控制不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
DHIS 2 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
DHIS 2是一个应用软件。一个灵活的信息系统,用于数据捕获、管理、验证、分析和可视化。 DHIS 2 2.37.9.1之前版本、2.38.3.1 之前版本和 2.39.1.2 之前版本存在安全漏洞,该漏洞源于在 PATCH 请求的负载中使用对象模型遍历,对对象具有写访问权限的用户可能能够修改相关对象。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
dhis2dhis2-core >= 2.36, < 2.37.9.1 -
II. Public POCs for CVE-2023-31138
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2023-31138
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2023-31138

No comments yet


Leave a comment