Intel

AIKIDO-2024-10120

helix.fhir.client.sdk is vulnerable to Insertion of Sensitive Information into Log File

Insertion of Sensitive Information into Log File Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jun 4, 2024

50

Medium Risk

This Affects:

pythonhelix.fhir.client.sdk
0.1.24 - 2.0.7
Fixed in 2.0.8
Are you affected? Scan for Free

TL;DR

Affected versions of helix.fhir.client.sdk could expose HTTP headers in the logs. Since HTTP headers may contain authentication details, this could lead to sensitive information being logged in your logging system.

Who does this affect?

You are affected if you are use a vulnerable version of helix.fhir.client.sdk.

Background info

helix.fhir.client.sdk is vulnerable to Insertion of Sensitive Information into Log File in versions 0.1.24 - 2.0.7.

How to fix this

Upgrade helix.fhir.client.sdk to the patch version (version 2.0.8).