CVE-2022-39230 – fhir-works-on-aws-authz-smart
Package
Manager: npm
Name: fhir-works-on-aws-authz-smart
Vulnerable Version: >=3.1.1 <3.1.3
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
EPSS: 0.00115 pctl0.30911
Details
fhir-works-on-aws-authz-smart handles permissions improperly ### Impact This issue allows a client of the API to retrieve more information than the client’s OAuth scope permits when making “search-type” requests. This issue would not allow a client to retrieve information about individuals other than those the client was already authorized to access. ### Patches We recommend that users of fhir-works-on-aws-authz-smart 3.1.1 or 3.1.2 upgrade to version 3.1.3 or higher immediately. Versions 3.1.0 and below are unaffected. ### Workarounds There is no workaround for this issue. Please upgrade fhir-works-on-aws-authz-smart to version 3.1.3 or higher. ### References https://github.com/awslabs/fhir-works-on-aws-deployment https://github.com/awslabs/fhir-works-on-aws-authz-smart ### For more information If you have any questions or comments about this advisory: Email us at [fhir-works-on-aws-dev@amazon.com](mailto:fhir-works-on-aws-dev@amazon.com)
Metadata
Created: 2022-09-21T20:36:50Z
Modified: 2022-09-27T06:12:12Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-vv7x-7w4m-q72f/GHSA-vv7x-7w4m-q72f.json
CWE IDs: ["CWE-200", "CWE-281"]
Alternative ID: GHSA-vv7x-7w4m-q72f
Finding: F159
Auto approve: 1