CVE-2023-31139: DHIS2 Core contains the service layer and Web API for DHIS2,..
May 9, 2023
May 16, 2023
DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.37 branch and prior to versions 18.104.22.168, 22.214.171.124, and 126.96.36.199, Personal Access Tokens (PATs) generate unrestricted session cookies. This may lead to a bypass of other access restrictions (for example, based on allowed IP addresses or HTTP methods). DHIS2 implementers should upgrade to a supported version of DHIS2: 188.8.131.52, 184.108.40.206, or 220.127.116.11. Implementers can work around this issue by adding extra access control validations on a reverse proxy.
CVSS base metrics
Learn from academy
What is API?
Types of APIs
GraphQL vs REST
REST vs SOAP
GET vs POST
PUT vs POST
GraphQL Authentication and Authorization
Swagger for API Documentation
Explore more from Akto
Be updated about everything related to API Security, new API vulnerabilities, industry news and product updates.
Discover and find tests from Akto's 100+ API Security test library. Choose your template or add a new template to start your API Security testing.
Check out Akto's product documentation for all information related to features and how to use them.