CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

OHIF Viewers DICOM

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 272

As cited

Copy frozen at (site build).

vulnerabilities

OHIF Viewers DICOM

The Open Health Imaging Foundation (OHIF) DICOM Web Viewer Framework versions 3.12.0 and earlier contain a server-side request forgery (SSRF) vulnerability in the DICOMWebProxy and DICOMJSON data sources. An attacker could exploit this vulnerability via a crafted link to steal an authenticated clinician's OIDC Bearer token by redirecting requests to an attacker-controlled server. OHIF released version 3.12.2 with a fix and recommends upgrading immediately, along with configuring an allowlist for authenticated deployments or removing unused data source configurations.

Why it matters: Healthcare organizations running OHIF versions 3.12.0 or earlier with authentication enabled should upgrade urgently to prevent token theft that could compromise clinician accounts and patient data access.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

OHIF Viewers DICOM

The Open Health Imaging Foundation (OHIF) DICOM Web Viewer Framework versions 3.12.0 and earlier contain a server-side request forgery (SSRF) vulnerability in the DICOMWebProxy and DICOMJSON data sources. An attacker could exploit this vulnerability via a crafted link to steal an authenticated clinician's OIDC Bearer token by redirecting requests to an attacker-controlled server. OHIF released version 3.12.2 with a fix and recommends upgrading immediately, along with configuring an allowlist for authenticated deployments or removing unused data source configurations.

Why it matters: Healthcare organizations running OHIF versions 3.12.0 or earlier with authentication enabled should upgrade urgently to prevent token theft that could compromise clinician accounts and patient data access.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary