漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
OpenEMR 8.2.0 OAuth2 Password Grant Authentication Bypass via SMART Configuration
Vulnerability Description
OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to circumvent multi-factor authentication by exploiting the exposed OAuth2 password grant flow through an unauthenticated client registration endpoint. Attackers can register an OAuth2 client via the unauthenticated registration endpoint and use the password grant to exchange credentials for an API access token, bypassing the normal web interface authentication and any enforced multi-factor authentication controls.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
使用单一因素认证机制
Vulnerability Title
OpenEMR 授权问题漏洞
Vulnerability Description
openemr是OpenEMR组织开源的一个支持文档管理与企业应用场景的医疗信息管理平台。 OpenEMR 8.2.0及之前版本存在授权问题漏洞,该漏洞源于暴露的OAuth2密码授权流程和未认证的客户端注册端点,可能导致具有有效凭据的攻击者绕过多因素认证,注册OAuth2客户端并使用密码授权交换API访问令牌,从而绕过正常的Web界面认证和多因素认证控制。
CVSS Information
N/A
Vulnerability Type
N/A