DHIS2 Core vulnerable to Improper Access Control with PATCH requests
CVE-2023-31138
7.1HIGH
What is CVE-2023-31138?
DHIS2 Core has a security issue that allows authenticated users with write access to exploit object model traversal in the payload of a PATCH request. This vulnerability enables users to modify related objects without proper authorization, which could compromise data integrity and security. Organizations using DHIS2 should promptly upgrade to versions 2.37.9.1, 2.38.3.1, or 2.39.1.2 to mitigate this risk. Alternatively, blocking PATCH requests through a reverse proxy can serve as an interim solution, though it may disrupt functionality for applications relying on legacy PATCH requests.
Affected Version(s)
dhis2-core >= 2.36, < 2.37.9.1 < 2.36, 2.37.9.1
dhis2-core >= 2.38, < 2.38.3.1 < 2.38, 2.38.3.1
dhis2-core >= 2.39, < 2.39.1.2 < 2.39, 2.39.1.2
