### Impact Any network-reachable caller can write arbitrary documents to any patient's electronic health record accessible by the institution's SMC-B card. In a misconfigured deployment (e.g., following the production Docker example in the README), this is exploitable from the local network without credentials. ### Patches - [#43](https://github.com/oviva-ag/epa4all-client/pull/43) ### Workarounds Use network policies or proxies to enforce service-to-service authentication via e.g. mTLS. - run the service in an isolated network namespace e.g. as Kubernetes sidecar - service-mesh with corresponding policies ### References - MS-OVIVA-EPA4ALL-8b2af7 ### Credits [Machine Spirits](https://machinespirits.com/) ([[email protected]](mailto:[email protected])) - Dr. rer. nat. Simon Weber - Dipl.-Inf. Volker Schönefeld - Chiara Fliegner
Monitor this advisory for an available fix and review any installs of the affected package.
Local check
hol-guard supply-chain scanepa4all-client: Unauthenticated REST API for Patient Record Writes affects com.oviva.telematik:epa4all-rest-service (maven). Severity is medium. ### Impact Any network-reachable caller can write arbitrary documents to any patient's electronic health record accessible by the institution's SMC-B card. In a misconfigured deployment (e.g., following the production Docker example in the README), this is exploitable from the local network without credentials. ### Patches - [#43](https://github.com/oviva-ag/epa4all-client/pull/43) ### Workarounds Use network policies or proxies to enforce service-to-service authentication via e.g. mTLS. - run the service in an isolated network namespace e.g. as Kubernetes sidecar - service-mesh with corresponding policies ### References - MS-OVIVA-EPA4ALL-8b2af7 ### Credits [Machine Spirits](https://machinespirits.com/) ([[email protected]](mailto:[email protected])) - Dr. rer. nat. Simon Weber - Dipl.-Inf. Volker Schönefeld - Chiara Fliegner
AI coding agents often install or upgrade packages automatically in maven. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|
### Impact Any network-reachable caller can write arbitrary documents to any patient's electronic health record accessible by the institution's SMC-B card. In a misconfigured deployment (e.g., following the production Docker example in the README), this is exploitable from the local network without credentials. ### Patches - [#43](https://github.com/oviva-ag/epa4all-client/pull/43) ### Workarounds Use network policies or proxies to enforce service-to-service authentication via e.g. mTLS. - run the service in an isolated network namespace e.g. as Kubernetes sidecar - service-mesh with corresponding policies ### References - MS-OVIVA-EPA4ALL-8b2af7 ### Credits [Machine Spirits](https://machinespirits.com/) ([[email protected]](mailto:[email protected])) - Dr. rer. nat. Simon Weber - Dipl.-Inf. Volker Schönefeld - Chiara Fliegner
Monitor this advisory for an available fix and review any installs of the affected package.
Local check
hol-guard supply-chain scanepa4all-client: Unauthenticated REST API for Patient Record Writes affects com.oviva.telematik:epa4all-rest-service (maven). Severity is medium. ### Impact Any network-reachable caller can write arbitrary documents to any patient's electronic health record accessible by the institution's SMC-B card. In a misconfigured deployment (e.g., following the production Docker example in the README), this is exploitable from the local network without credentials. ### Patches - [#43](https://github.com/oviva-ag/epa4all-client/pull/43) ### Workarounds Use network policies or proxies to enforce service-to-service authentication via e.g. mTLS. - run the service in an isolated network namespace e.g. as Kubernetes sidecar - service-mesh with corresponding policies ### References - MS-OVIVA-EPA4ALL-8b2af7 ### Credits [Machine Spirits](https://machinespirits.com/) ([[email protected]](mailto:[email protected])) - Dr. rer. nat. Simon Weber - Dipl.-Inf. Volker Schönefeld - Chiara Fliegner
AI coding agents often install or upgrade packages automatically in maven. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|
| com.oviva.telematik:epa4all-rest-servicemaven | <=1.2.4 | Not reported |
|---|
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| com.oviva.telematik:epa4all-rest-servicemaven | <=1.2.4 | Not reported |
|---|
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard