Orthanc server prior to version 1.5.8 does not enable basic authentication by default when remote access is enabled. This could result in unauthorized access by an attacker.
{
"binaries": [
{
"binary_name": "liborthancframework-dev",
"binary_version": "1.10.0+dfsg-1"
},
{
"binary_name": "liborthancframework1",
"binary_version": "1.10.0+dfsg-1"
},
{
"binary_name": "orthanc",
"binary_version": "1.10.0+dfsg-1"
},
{
"binary_name": "orthanc-dev",
"binary_version": "1.10.0+dfsg-1"
}
]
}{
"binaries": [
{
"binary_name": "liborthancframework-dev",
"binary_version": "1.12.2+dfsg-1build4"
},
{
"binary_name": "liborthancframework1",
"binary_version": "1.12.2+dfsg-1build4"
},
{
"binary_name": "orthanc",
"binary_version": "1.12.2+dfsg-1build4"
},
{
"binary_name": "orthanc-dev",
"binary_version": "1.12.2+dfsg-1build4"
}
]
}{
"binaries": [
{
"binary_name": "liborthancframework-dev",
"binary_version": "1.12.6+dfsg-1"
},
{
"binary_name": "liborthancframework1",
"binary_version": "1.12.6+dfsg-1"
},
{
"binary_name": "orthanc",
"binary_version": "1.12.6+dfsg-1"
},
{
"binary_name": "orthanc-dev",
"binary_version": "1.12.6+dfsg-1"
}
]
}{
"binaries": [
{
"binary_name": "liborthancframework-dev",
"binary_version": "1.12.7+dfsg-4build2"
},
{
"binary_name": "liborthancframework1",
"binary_version": "1.12.7+dfsg-4build2"
},
{
"binary_name": "orthanc",
"binary_version": "1.12.7+dfsg-4build2"
},
{
"binary_name": "orthanc-dev",
"binary_version": "1.12.7+dfsg-4build2"
}
]
}