Orthanc versions before 1.12.2 are affected by a reflected cross-site scripting (XSS) vulnerability. The vulnerability was present in the server's error reporting.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1.12.2+dfsg-1", "binary_name": "liborthancframework-dev" }, { "binary_version": "1.12.2+dfsg-1", "binary_name": "liborthancframework1" }, { "binary_version": "1.12.2+dfsg-1", "binary_name": "liborthancframework1-dbgsym" }, { "binary_version": "1.12.2+dfsg-1", "binary_name": "orthanc" }, { "binary_version": "1.12.2+dfsg-1", "binary_name": "orthanc-dbgsym" }, { "binary_version": "1.12.2+dfsg-1", "binary_name": "orthanc-dev" }, { "binary_version": "1.12.2+dfsg-1", "binary_name": "orthanc-doc" } ] }