There are 2 open security issues in bookworm.
1 important issue:
- CVE-2025-15581:
Orthanc versions before 1.12.10 are affected by an authorisation logic flaw in the application's HTTP Basic Authentication implementation. Successful exploitation could result in Privilege Escalation, potentially allowing full administrative access.
1 issue left for the package maintainer to handle:
- CVE-2024-22725:
(needs triaging)
Orthanc versions before 1.12.2 are affected by a reflected cross-site scripting (XSS) vulnerability. The vulnerability was present in the server's error reporting.
You can find information about how to handle this issue in the security team's documentation.