漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
ePA 3.x Integration: HTTP Header Injection in VAU Inner Requests
Vulnerability Description
ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration does not neutralize CRLF characters in values used by app/vau/VAUProtokoll.py to construct VAU inner HTTP requests. The build_inner_header function interpolates the uri, host, accept_type, content_type, content_length, USER_AGENT, and insurant_id values into request lines and headers, including x-useragent and x-insurantid. An authenticated attacker who controls a value can inject additional headers into the inner request. Depending on ePA server handling, an injected x-insurantid header can expose another patient's records, and injected Authorization headers can bypass the intended authentication or authorization context. Session-derived USER_AGENT input can also poison requests across the session. This issue is fixed in version 1.3.0.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
HTTP头部中CRLF序列转义处理不恰当(HTTP响应分割)
Vulnerability Title
fbeta ePA 3.x Integration 输入验证错误漏洞
Vulnerability Description
fbeta ePA 3.x Integration是德国fbeta公司的一款Web服务集成组件。 fbeta ePA 3.x Integration1.3.0之前版本存在输入验证错误漏洞,该漏洞源于未中和CRLF字符,可能导致经过身份验证的攻击者注入额外标头,暴露其他患者记录或绕过身份验证和授权。
CVSS Information
N/A
Vulnerability Type
N/A