DHIS2 Core unrestricted session cookies with Personal Access Tokens
CVE-2023-31139
4.3MEDIUM
What is CVE-2023-31139?
A vulnerability in DHIS2 Core allows Personal Access Tokens (PATs) to generate unrestricted session cookies. This can lead to the circumvention of established access restrictions, such as IP whitelisting and HTTP method limitations. Users of affected versions should upgrade to versions 2.37.9.1, 2.38.3.1, or 2.39.1.2. Alternatively, implementing additional access control measures on a reverse proxy can mitigate the risk.
Affected Version(s)
dhis2-core >= 2.37, < 2.37.9.1 < 2.37, 2.37.9.1
dhis2-core >= 2.38, < 2.38.3.1 < 2.38, 2.38.3.1
dhis2-core >= 2.39, < 2.39.1.2 < 2.39, 2.39.1.2
