OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitrary commands on the targeted system via crafted XML data in a request body.
{
"cpe": "cpe:2.3:a:openmrs:openmrs:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "1.12.0"
},
{
"fixed": "1.12.1"
},
{
"introduced": "2.0.0"
},
{
"fixed": "2.0.8"
},
{
"introduced": "2.1.0"
},
{
"fixed": "2.1.4"
}
],
"source": "CPE_RANGE"
}