PT-2021-19870 · Dhis2 · Dhis2

Published

2021-06-24

·

Updated

2021-07-08

·

CVE-2021-32704

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DHIS2 versions 2.34.4, 2.35.2, 2.35.3, 2.35.4, and 2.36.0
Description A SQL injection security issue has been found in DHIS2, affecting the "/api/trackedEntityInstances" API endpoint. This issue can be exploited by logged-in users, allowing them to read, edit, and delete data in the DHIS2 instance. There are no known exploits of this issue, but it is recommended that all DHIS2 implementations using affected versions install patches as soon as possible.
Recommendations For versions 2.34.4, 2.35.2, 2.35.3, 2.35.4, and 2.36.0, upgrade the affected DHIS2 server to a patched version. For implementations using Tracker functionality, there is no known workaround other than upgrading. For implementations not using Tracker functionality, consider blocking all network access to POST requests to the "/api/trackedEntityInstances" endpoint as a temporary workaround while waiting to upgrade.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-32704
GHSA-FJ38-585H-HXGJ

Affected Products

Dhis2