CVE Vulnerabilities

CVE-2022-1459

Insufficient Documentation of Error Handling Techniques

Published: Apr 25, 2022 | Modified: Nov 21, 2024
CVSS 3.x
8.3
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Non-Privilege User Can View Patient’s Disclosures in GitHub repository openemr/openemr prior to 6.1.0.1.

Weakness

The documentation does not sufficiently describe the techniques that are used for error handling, exception processing, or similar mechanisms.

Affected Software

Name Vendor Start Version End Version
Openemr Open-emr * 6.1.0.1 (excluding)

Extended Description

Documentation may need to cover error handling techniques at multiple layers, such as module, executable, compilable code unit, or callable.

References