Skip to content

FHIR2 Module Privileges

Critical
gracepotma published GHSA-g5vq-w8v2-4x9j May 27, 2025

Package

FHIR2 (OpenMRS)

Affected versions

<2.5.0

Patched versions

2.5.0 and above

Description

OpenMRS Security Advisory

Please be aware of the following security vulnerability.

Severity: Critical

Affected Versions

  • FHIR2 Module versions < 2.5.0

Vulnerability

  • In versions of the FHIR2 module prior to 2.5.0, privileges were not always correctly checked, which means that unauthorized users may have been able to add or edit data they were not supposed to be able to.

Recommendations
All implementers should update to FHIR2 2.5.0 or newer as soon as is feasible.

For questions or concerns, connect with the OpenMRS Security Group at [email protected].

Severity

Critical

CVE ID

CVE-2025-46823

Weaknesses

No CWEs