Orthanc server prior to version 1.5.8 does not enable basic authentication by default when remote access is enabled. This could result in unauthorized access by an attacker.
{
"binaries": [
{
"binary_version": "1.10.0+dfsg-1",
"binary_name": "liborthancframework-dev"
},
{
"binary_version": "1.10.0+dfsg-1",
"binary_name": "liborthancframework1"
},
{
"binary_version": "1.10.0+dfsg-1",
"binary_name": "orthanc"
},
{
"binary_version": "1.10.0+dfsg-1",
"binary_name": "orthanc-dev"
}
]
}{
"binaries": [
{
"binary_version": "1.12.2+dfsg-1build4",
"binary_name": "liborthancframework-dev"
},
{
"binary_version": "1.12.2+dfsg-1build4",
"binary_name": "liborthancframework1"
},
{
"binary_version": "1.12.2+dfsg-1build4",
"binary_name": "orthanc"
},
{
"binary_version": "1.12.2+dfsg-1build4",
"binary_name": "orthanc-dev"
}
]
}{
"binaries": [
{
"binary_version": "1.12.6+dfsg-1",
"binary_name": "liborthancframework-dev"
},
{
"binary_version": "1.12.6+dfsg-1",
"binary_name": "liborthancframework1"
},
{
"binary_version": "1.12.6+dfsg-1",
"binary_name": "orthanc"
},
{
"binary_version": "1.12.6+dfsg-1",
"binary_name": "orthanc-dev"
}
]
}{
"binaries": [
{
"binary_version": "1.12.7+dfsg-4build2",
"binary_name": "liborthancframework-dev"
},
{
"binary_version": "1.12.7+dfsg-4build2",
"binary_name": "liborthancframework1"
},
{
"binary_version": "1.12.7+dfsg-4build2",
"binary_name": "orthanc"
},
{
"binary_version": "1.12.7+dfsg-4build2",
"binary_name": "orthanc-dev"
}
]
}