johnperry / CTP

Clinical Trial Processor
http://mircwiki.rsna.org/index.php?title=CTP_Articles
65 stars 55 forks source link

Security issue with HttpExportService to XNAT #34

Open pfcgroot opened 1 year ago

pfcgroot commented 1 year ago

It seems that the user credentials that are used to connect to xnat, are visible in the public web interface. (I.e., when visiting as guest.)

image

Thanks in advance for fixing. Paul

johnperry commented 1 year ago

The issue is fixed. It is in the CTP-installer.jar in the repo's products directory. I'll put it on the RSNA MIRC site soon.