Skip to content

fhir-works-on-aws-authz-smart handles permissions improperly

Moderate severity GitHub Reviewed Published Sep 20, 2022 in awslabs/fhir-works-on-aws-authz-smart • Updated Jan 27, 2023

Package

npm fhir-works-on-aws-authz-smart (npm)

Affected versions

>= 3.1.1, < 3.1.3

Patched versions

3.1.3

Description

Impact

This issue allows a client of the API to retrieve more information than the client’s OAuth scope permits when making “search-type” requests. This issue would not allow a client to retrieve information about individuals other than those the client was already authorized to access.

Patches

We recommend that users of fhir-works-on-aws-authz-smart 3.1.1 or 3.1.2 upgrade to version 3.1.3 or higher immediately. Versions 3.1.0 and below are unaffected.

Workarounds

There is no workaround for this issue. Please upgrade fhir-works-on-aws-authz-smart to version 3.1.3 or higher.

References

https://github.com/awslabs/fhir-works-on-aws-deployment
https://github.com/awslabs/fhir-works-on-aws-authz-smart

For more information

If you have any questions or comments about this advisory:

Email us at fhir-works-on-aws-dev@amazon.com

References

Published to the GitHub Advisory Database Sep 21, 2022
Reviewed Sep 21, 2022
Published by the National Vulnerability Database Sep 23, 2022
Last updated Jan 27, 2023

Severity

Moderate
6.5
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CVE ID

CVE-2022-39230

GHSA ID

GHSA-vv7x-7w4m-q72f
Checking history
See something to contribute? Suggest improvements for this vulnerability.