{"id":"CVE-2022-24848","summary":"SQL Injection in DHIS2's in OrgUnit program association","details":"DHIS2 is an information system for data capture, management, validation, analytics and visualization. A SQL injection security vulnerability affects the `/api/programs/orgUnits?programs=` API endpoint in DHIS2 versions prior to 2.36.10.1 and 2.37.6.1. The system is vulnerable to attack only from users that are logged in to DHIS2, and there is no known way of exploiting the vulnerability without first being logged in as a DHIS2 user. The vulnerability is not exposed to a non-malicious user and requires a conscious attack to be exploited. A successful exploit of this vulnerability could allow the malicious user to read, edit and delete data in the DHIS2 instance's database. Security patches are now available for DHIS2 versions 2.36.10.1 and 2.37.6.1. One may apply mitigations at the web proxy level as a workaround. More information about these mitigations is available in the GitHub Security Advisory.","aliases":["GHSA-52vp-f7hj-cj92"],"modified":"2026-08-12T13:00:38.561999Z","published":"2022-06-01T17:20:14Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-89"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/24xxx/CVE-2022-24848.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/24xxx/CVE-2022-24848.json"},{"type":"ADVISORY","url":"https://github.com/dhis2/dhis2-core/security/advisories/GHSA-52vp-f7hj-cj92"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-24848"},{"type":"FIX","url":"https://github.com/dhis2/dhis2-core/commit/3b245d04a58b78f0dc9bae8559f36ee4ca36dfac"},{"type":"FIX","url":"https://github.com/dhis2/dhis2-core/commit/ef04483a9b177d62e48dcf4e498b302a11f95e7d"},{"type":"FIX","url":"https://github.com/dhis2/dhis2-core/pull/10953"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/dhis2/dhis2-core","events":[{"introduced":"0"},{"fixed":"51a01941359394fdb0ff1abd9bd290c25f785135"},{"introduced":"b8d4ef368ffa769034b36e143551be28a671c12c"},{"fixed":"2e2f4d9a6c951f48903e6c1bbd44d8002046068b"},{"fixed":"3b245d04a58b78f0dc9bae8559f36ee4ca36dfac"},{"fixed":"ef04483a9b177d62e48dcf4e498b302a11f95e7d"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:dhis2:dhis_2:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.36.10.1"},{"introduced":"2.37.0"},{"fixed":"2.37.6.1"}]}}],"versions":["2.36.10","2.37.6","2.37.5","2.36.9","2.37.4","2.36.8","2.37.3"],"database_specific":{"vanir_signatures_modified":"2026-08-12T13:00:38Z","vanir_signatures":[{"target":{"file":"dhis-2/dhis-services/dhis-service-core/src/test/java/org/hisp/dhis/common/IdentifiableObjectManagerTest.java"},"deprecated":false,"digest":{"line_hashes":["102466045036280647411433231181054736435","114261828675937922713711569831631637368","303467415364703095546560637036701689057","130111986188381043105689039232246868169","187664006860825395867380058438136504132","269136619053545228727579492767101957127","134522533693129076533408915783520956542","153596538825215481310882350129053127813","38224302443409359024492866527326987157","292539234028683227485573031959051217882","178316045186907953133521537768511529550","302992013328606286401055715409336125308"],"threshold":0.9},"id":"CVE-2022-24848-0ad556b0","signature_type":"Line","signature_version":"v1","source":"https://github.com/dhis2/dhis2-core/commit/3b245d04a58b78f0dc9bae8559f36ee4ca36dfac"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/dhis2/dhis2-core/commit/ef04483a9b177d62e48dcf4e498b302a11f95e7d","target":{"file":"dhis-2/dhis-services/dhis-service-core/src/main/java/org/hisp/dhis/association/AbstractOrganisationUnitAssociationsQueryBuilder.java","function":"withQuotes"},"deprecated":false,"digest":{"function_hash":"249354532457910431061934106965650152129","length":87},"id":"CVE-2022-24848-0e709805"},{"digest":{"line_hashes":["57399657551283052044233459628795904877","316249293392211649537767491204817149632","303813605954198171243780890322794520077","196959916236655327898879482034354541915","104893718468063290041140674323407089327","251139140867108837825285634598205717997","90035616123137066354681332460715421949","184551110194354917370221405731436762875"],"threshold":0.9},"id":"CVE-2022-24848-13d21f5d","signature_type":"Line","signature_version":"v1","source":"https://github.com/dhis2/dhis2-core/commit/3b245d04a58b78f0dc9bae8559f36ee4ca36dfac","target":{"file":"dhis-2/dhis-services/dhis-service-core/src/main/java/org/hisp/dhis/common/DefaultIdentifiableObjectManager.java"},"deprecated":false},{"target":{"file":"dhis-2/dhis-services/dhis-service-core/src/test/java/org/hisp/dhis/common/IdentifiableObjectManagerTest.java"},"deprecated":false,"digest":{"line_hashes":["102466045036280647411433231181054736435","114261828675937922713711569831631637368","303467415364703095546560637036701689057","130111986188381043105689039232246868169","187664006860825395867380058438136504132","269136619053545228727579492767101957127","134522533693129076533408915783520956542","153596538825215481310882350129053127813","292539234028683227485573031959051217882","178316045186907953133521537768511529550","302992013328606286401055715409336125308"],"threshold":0.9},"id":"CVE-2022-24848-1cb96ded","signature_type":"Line","signature_version":"v1","source":"https://github.com/dhis2/dhis2-core/commit/ef04483a9b177d62e48dcf4e498b302a11f95e7d"},{"id":"CVE-2022-24848-26e726d2","signature_type":"Line","signature_version":"v1","source":"https://github.com/dhis2/dhis2-core/commit/ef04483a9b177d62e48dcf4e498b302a11f95e7d","target":{"file":"dhis-2/dhis-support/dhis-support-commons/src/main/java/org/hisp/dhis/commons/collection/CollectionUtils.java"},"deprecated":false,"digest":{"line_hashes":["230032702892572446585665732616235806875","112540260926753227667748316354775628849","272470979061361285969218539944531303041","3879568424579650423314572074935124455","125654131591926760930841726699124464068","9587559197160270830447331689312492905","10038586363840711724339347800510718827"],"threshold":0.9}},{"digest":{"line_hashes":["230032702892572446585665732616235806875","112540260926753227667748316354775628849","272470979061361285969218539944531303041","3879568424579650423314572074935124455","230322696606718175473127719822195904072","125654131591926760930841726699124464068","9587559197160270830447331689312492905","10038586363840711724339347800510718827"],"threshold":0.9},"id":"CVE-2022-24848-316426c3","signature_type":"Line","signature_version":"v1","source":"https://github.com/dhis2/dhis2-core/commit/3b245d04a58b78f0dc9bae8559f36ee4ca36dfac","target":{"file":"dhis-2/dhis-support/dhis-support-commons/src/main/java/org/hisp/dhis/commons/collection/CollectionUtils.java"},"deprecated":false},{"deprecated":false,"digest":{"line_hashes":["125966001357542018660590465863555813718","294631969892695770579401761970646453615","192956881756632128168761032921202774408","95658218599678879158695340570823834938"],"threshold":0.9},"id":"CVE-2022-24848-471381d2","signature_type":"Line","signature_version":"v1","source":"https://github.com/dhis2/dhis2-core/commit/ef04483a9b177d62e48dcf4e498b302a11f95e7d","target":{"file":"dhis-2/dhis-api/src/main/java/org/hisp/dhis/feedback/ErrorCode.java"}},{"signature_version":"v1","source":"https://github.com/dhis2/dhis2-core/commit/ef04483a9b177d62e48dcf4e498b302a11f95e7d","target":{"file":"dhis-2/dhis-services/dhis-service-core/src/main/java/org/hisp/dhis/association/AbstractOrganisationUnitAssociationsQueryBuilder.java","function":"jsonbFunction"},"deprecated":false,"digest":{"function_hash":"241704228489475477578107098675663980606","length":258},"id":"CVE-2022-24848-487b6201","signature_type":"Function"},{"signature_version":"v1","source":"https://github.com/dhis2/dhis2-core/commit/3b245d04a58b78f0dc9bae8559f36ee4ca36dfac","target":{"file":"dhis-2/dhis-support/dhis-support-system/src/main/java/org/hisp/dhis/system/util/SqlUtils.java"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["22686580689272752327519434059015666360","250630746096453564215874513139945590237","127823224835131912240413426583014596393","85583486930108575640796271003646310862","147425159016743277562250030464353869112","334670507166284032251078829323300187210","64549923015395307828451644935861241685","133062632243648067751483377189797129595"]},"id":"CVE-2022-24848-5404e158","signature_type":"Line"},{"source":"https://github.com/dhis2/dhis2-core/commit/ef04483a9b177d62e48dcf4e498b302a11f95e7d","target":{"file":"dhis-2/dhis-services/dhis-service-core/src/main/java/org/hisp/dhis/association/AbstractOrganisationUnitAssociationsQueryBuilder.java","function":"getUidsFilter"},"deprecated":false,"digest":{"function_hash":"124679769609649065978171997477956327843","length":160},"id":"CVE-2022-24848-5697636f","signature_type":"Function","signature_version":"v1"},{"signature_version":"v1","source":"https://github.com/dhis2/dhis2-core/commit/ef04483a9b177d62e48dcf4e498b302a11f95e7d","target":{"file":"dhis-2/dhis-services/dhis-service-core/src/main/java/org/hisp/dhis/common/DefaultIdentifiableObjectManager.java"},"deprecated":false,"digest":{"line_hashes":["19559157705129784496445654486348157863","281222190206516001808137137820194235049","99933412339175387404024294981173936915","98440773895098382638870808262113027323","279514443160030423527183333733081846518","49251727525521315591457999748078364669","184551110194354917370221405731436762875"],"threshold":0.9},"id":"CVE-2022-24848-6b1f9722","signature_type":"Line"},{"deprecated":false,"digest":{"line_hashes":["250055276200707292554644998191054532006","261258551620232808486287110972716043524","13669437031653493553166344095401763935","79522653668005664094394176741918988645","96222283951497928925522111503616552572","144897015539422385755780156870658269596","213743678774965529481273098432220144156","34198473564778365933978116055562266703","79251540907864295387380452539655632365","243268373162569927889488894684846496580","210985144205305688034413797982160960361","47333422812668402688178392781944334702","29159107061371187261878897906088191161","175235215973363708716448689645009665137","21301824944071899232318002759470123313","50661066958745683818200156205046244207","300446311414252902431715125929078838714","269449537359171193260852719892938707741","103955104354647918476838727990889917800","163696343067535432253940821694718741500","30555398915813802178584318414013207622","228334725635767012689284919493571570220","245195475607782705047435559349318965004","16430250845156314496284572386285077612","235593061652953828660087712189478857518","139632684898472940585426616670404725754","171812548289999046796777609852393912198","64612423127741265847395342554906172785","13516371769838844059663508087080217137","197441887843897458104179407408323954715","290264812695737067826605041770554719656","295807382624270280277214593015787107117","19622248238908113947169261109000136093"],"threshold":0.9},"id":"CVE-2022-24848-885cd66d","signature_type":"Line","signature_version":"v1","source":"https://github.com/dhis2/dhis2-core/commit/ef04483a9b177d62e48dcf4e498b302a11f95e7d","target":{"file":"dhis-2/dhis-services/dhis-service-core/src/main/java/org/hisp/dhis/association/AbstractOrganisationUnitAssociationsQueryBuilder.java"}},{"source":"https://github.com/dhis2/dhis2-core/commit/3b245d04a58b78f0dc9bae8559f36ee4ca36dfac","target":{"file":"dhis-2/dhis-api/src/main/java/org/hisp/dhis/common/IdentifiableObjectManager.java"},"deprecated":false,"digest":{"line_hashes":["54048382112955460386833552618838585513","219840286585150624504653147956905776963","100446472688414604393198918215183094567","82391701401985751672492586163978488017"],"threshold":0.9},"id":"CVE-2022-24848-9278164c","signature_type":"Line","signature_version":"v1"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/dhis2/dhis2-core/commit/3b245d04a58b78f0dc9bae8559f36ee4ca36dfac","target":{"function":"getProgramUidsFilter","file":"dhis-2/dhis-services/dhis-service-core/src/main/java/org/hisp/dhis/association/ProgramOrganisationUnitAssociationsQueryBuilder.java"},"deprecated":false,"digest":{"function_hash":"293545676171341896680418887783457333661","length":152},"id":"CVE-2022-24848-a2eb2285"},{"signature_version":"v1","source":"https://github.com/dhis2/dhis2-core/commit/ef04483a9b177d62e48dcf4e498b302a11f95e7d","target":{"file":"dhis-2/dhis-api/src/main/java/org/hisp/dhis/common/IdentifiableObjectManager.java"},"deprecated":false,"digest":{"line_hashes":["277032719948894478627065389357670120019","21489341386493563515144480964134376342","217903988964777180682749212263774870670","143095084474733366784294673255312668378"],"threshold":0.9},"id":"CVE-2022-24848-b640923f","signature_type":"Line"},{"source":"https://github.com/dhis2/dhis2-core/commit/3b245d04a58b78f0dc9bae8559f36ee4ca36dfac","target":{"file":"dhis-2/dhis-services/dhis-service-core/src/main/java/org/hisp/dhis/association/ProgramOrganisationUnitAssociationsQueryBuilder.java","function":"jsonbFunction"},"deprecated":false,"digest":{"function_hash":"197004765800089766531704963020310066812","length":244},"id":"CVE-2022-24848-e19d9ab9","signature_type":"Function","signature_version":"v1"},{"deprecated":false,"digest":{"line_hashes":["125966001357542018660590465863555813718","220583533023062392122210971426163780280","183662771406784182743536121697620250307","262144207171505419373373048553307794819"],"threshold":0.9},"id":"CVE-2022-24848-e23c8aa0","signature_type":"Line","signature_version":"v1","source":"https://github.com/dhis2/dhis2-core/commit/3b245d04a58b78f0dc9bae8559f36ee4ca36dfac","target":{"file":"dhis-2/dhis-api/src/main/java/org/hisp/dhis/feedback/ErrorCode.java"}},{"deprecated":false,"digest":{"line_hashes":["62890622429700287561056807304623251996","334115000323984010484606589478624971232","11675047249880076539404356017574094696","36204398983928385373248187219190431149","37718954169537731057097644749527304312","118384589542555582637479575044359801256","139381050555678046631849948991891977364","249122768960396662425600082456168093993","15456585988388524753763164063633319502","122547448200446782018477071542428434699","125464040077987209907154459994438351324","130644324948113138734109497622565580978","22518411942763966955817651070699260333"],"threshold":0.9},"id":"CVE-2022-24848-e35275b8","signature_type":"Line","signature_version":"v1","source":"https://github.com/dhis2/dhis2-core/commit/ef04483a9b177d62e48dcf4e498b302a11f95e7d","target":{"file":"dhis-2/dhis-services/dhis-service-core/src/main/java/org/hisp/dhis/program/DefaultProgramService.java"}},{"deprecated":false,"digest":{"function_hash":"249354532457910431061934106965650152129","length":87},"id":"CVE-2022-24848-e35c6220","signature_type":"Function","signature_version":"v1","source":"https://github.com/dhis2/dhis2-core/commit/3b245d04a58b78f0dc9bae8559f36ee4ca36dfac","target":{"file":"dhis-2/dhis-services/dhis-service-core/src/main/java/org/hisp/dhis/association/ProgramOrganisationUnitAssociationsQueryBuilder.java","function":"withQuotes"}},{"deprecated":false,"digest":{"function_hash":"8042832022735628658833595712186561598","length":426},"id":"CVE-2022-24848-ea33d5cc","signature_type":"Function","signature_version":"v1","source":"https://github.com/dhis2/dhis2-core/commit/ef04483a9b177d62e48dcf4e498b302a11f95e7d","target":{"file":"dhis-2/dhis-services/dhis-service-core/src/main/java/org/hisp/dhis/deduplication/hibernate/HibernatePotentialDuplicateStore.java","function":"auditTeav"}},{"source":"https://github.com/dhis2/dhis2-core/commit/ef04483a9b177d62e48dcf4e498b302a11f95e7d","target":{"file":"dhis-2/dhis-services/dhis-service-core/src/main/java/org/hisp/dhis/deduplication/hibernate/HibernatePotentialDuplicateStore.java"},"deprecated":false,"digest":{"line_hashes":["20618325070726611499389471522682031332","327019338463398564296862383525071457475","250778863563435109725696216653236500381","53629798486140609693556305890783055394","162645486164576749506952665693724058420","40547363094182621002051723203788307734","314650977312710515031939070477634624253","15364826547182728140444045679081693386","287922460737198964934188094640734393172","101577941340242561896870751059378561903","143725626434452094667073135656989883326","15924968818474745954723512825237200288","314477083253976313882636651483783065997","170405703639458475746159157440439499847","139198541484437292895221361774065157926","222515006654816133455618898786205750847","275670314574205042624487223245429251213","289735944416599191929631908817409166383","325993282181555655609713896235566691476","176600625978721660341360824882580816762","222214129272067081139380743905168391835","164017067646771709450872031789244988185","132769478403010964552476176074976753127","166012047266771941416205975877888043477","80253571796854887280563732370733053119"],"threshold":0.9},"id":"CVE-2022-24848-ed08e78c","signature_type":"Line","signature_version":"v1"},{"source":"https://github.com/dhis2/dhis2-core/commit/3b245d04a58b78f0dc9bae8559f36ee4ca36dfac","target":{"file":"dhis-2/dhis-services/dhis-service-core/src/main/java/org/hisp/dhis/association/ProgramOrganisationUnitAssociationsQueryBuilder.java"},"deprecated":false,"digest":{"line_hashes":["250055276200707292554644998191054532006","261258551620232808486287110972716043524","13669437031653493553166344095401763935","79522653668005664094394176741918988645","96222283951497928925522111503616552572","144897015539422385755780156870658269596","213743678774965529481273098432220144156","34198473564778365933978116055562266703","79251540907864295387380452539655632365","243268373162569927889488894684846496580","210985144205305688034413797982160960361","47333422812668402688178392781944334702","29159107061371187261878897906088191161","175235215973363708716448689645009665137","21301824944071899232318002759470123313","50661066958745683818200156205046244207","300446311414252902431715125929078838714","269449537359171193260852719892938707741","242003667548290712375068997660649854624","305494098306560811018131507738880494543","30555398915813802178584318414013207622","228334725635767012689284919493571570220","240331541001686722714389150561828115906","152115312187459907973466365492449394056","80512897842927746714639054810298373220","139632684898472940585426616670404725754","25765618622863743792304845810412274832","136572116540527437968436993070748846339","277026840073410027715633354772037057163","35021154985082624092173444900013787873","264232615410547788206328963757796274728","140754297116917515645657734178312203589","19622248238908113947169261109000136093"],"threshold":0.9},"id":"CVE-2022-24848-f7dcafcf","signature_type":"Line","signature_version":"v1"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-24848.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}