Security Alert Fixes

From OpenEMR Project Wiki
The printable version is no longer supported and may have rendering errors. Please update your browser bookmarks and please use the default browser print function instead.

Outdated issues from a long time ago.

Place to record and track OpenEMR security alerts and their fixes (in chronological order from earlier to later):

  • Fixed in most recent 4.0.0 patch and dev version
  • Fixed in most recent 4.0.0 patch and dev version
  • There are 4 items here:
  • The first two items likely still exist. A user needs to be authenticated(logged in) into OpenEMR to be able to do this; note a codebase refactoring is currently underway to fix these types of vulnerabilities.
  • The last 2 items will are fixed in most recent 4.1.1 patch and dev version.
  • This item is fixed in most recent 4.1.0 patch and dev version.
  • Fixed in most recent 4.1.0 patch and dev version
  • Fixed in most recent 4.1.0 patch and dev version
  • Fixed in most recent 4.1.0 patch and dev version
  • Fixed in most recent 4.1.1 patch and dev version
  • There are 8 items here:
  • The first item is same as the arbitrary file upload vulnerability item reported above and has been fixed in most recent 4.1.1 patch and dev version.
  • The second item likely still exists. A user needs to be authenticated(logged in) into OpenEMR to be able to do this; note a codebase refactoring is currently underway to fix these types of vulnerabilities.
  • The third item is fixed in most recent 4.1.1 patch and dev version.
  • The fourth item likely still exists. A user needs to be authenticated(logged in) into OpenEMR to be able to do this; note a codebase refactoring is currently underway to fix these types of vulnerabilities.
  • The fifth item is fixed in most recent 4.1.1 patch and dev version.
  • The sixth item is fixed in most recent 4.1.1 patch and dev version.
  • The seventh item is fixed in most recent 4.1.1 patch and dev version.
  • The eighth item is fixed in most recent 4.1.1 patch and dev version.
  • Fixed in most recent 4.1.1 patch and dev version
  • All the items have been fixed in most recent 4.1.1 patch and dev version.
  • CVE-2018-10571 - FIXED
  • CVE-2018-10572 - FIXED
  • CVE-2018-10573 - FIXED



TODO: