A flaw in the cohort search web service allowed users with permissions in lower contexts to access cohort information from the system context, revealing restricted administrative data.
{
"versions": [
{
"introduced": "4.1.0"
},
{
"fixed": "4.1.21"
},
{
"introduced": "4.4.0"
},
{
"fixed": "4.4.11"
},
{
"introduced": "4.5.0"
},
{
"fixed": "4.5.7"
},
{
"introduced": "5.0.0"
},
{
"fixed": "5.0.3"
}
]
}