CVE-2020-5733: Medium severity OpenMRS Openmrs vulnerability
In OpenMRS 2.9 and prior, the export functionality of the Data Exchange Module does not properly redirect to a login page when an unauthenticated user attempts to access it. This allows the export of potentially sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-5733?
CVE-2020-5733 is rated as a medium-severity vulnerability due to its potential risk of exposing sensitive information.
How do I fix CVE-2020-5733?
To fix CVE-2020-5733, upgrade OpenMRS to version 2.10 or later, which addresses the export functionality issue.
What type of vulnerability is CVE-2020-5733?
CVE-2020-5733 is an authentication bypass vulnerability related to improper redirection for unauthenticated users.
What can happen if I leave CVE-2020-5733 unpatched?
Leaving CVE-2020-5733 unpatched can potentially allow unauthorized access to sensitive data through the export functionality.
Which versions of OpenMRS are affected by CVE-2020-5733?
CVE-2020-5733 affects OpenMRS versions 2.9.0 and earlier.