CyberRota Analysis
AI-GeneratedThe /oauth2/register endpoint in Medplum versions 4.1.10 through 5.1.6 is vulnerable to information disclosure, potentially exposing the client_secret of preconfigured OAuth clients when a matching redirect_uri is supplied. This could allow unauthorized access to sensitive resources, making it critical for developers and organizations using Medplum to upgrade to version 5.1.7 immediately to mitigate the risk. Prioritization is essential for those in the healthcare app development sector to protect against potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Medplum is a developer platform that enables development of healthcare apps. In Medplum versions 4.1.10 through 5.1.6, the /oauth2/register endpoint could return the client_secret of preconfigured OAuth clients defined via the defaultOAuthClients server configuration when a matching redirect_uri was provided. This issue has been patched in version 5.1.7.