Gematik Authenticator securely authenticates users for login to digital health applications. Versions prior to 4.16.0 are vulnerable to authentication flow hijacking, potentially allowing attackers to authenticate with the identities of victim users who click on a malicious deep link. Update Gematik Authenticator to version 4.16.0 or greater to receive a patch. There are no known workarounds.
An attacker prepares a malicious deep link and tricks the victim into clicking it. After clicking, authentication flow hijacking occurs, allowing the attacker to authenticate in the system using the victim's identity. The vulnerability results from improper verification of the source of the authentication request (CWE-940 – Improper Verification of Source of a Communication Channel).
An attacker can hijack the victim's identity and gain unauthorized access to digital health applications that the user logs into, which may lead to breaches of confidentiality and integrity of protected health data.
Gematik Authenticator should be updated to version 4.16.0 or later. The vendor does not indicate any known workarounds for this vulnerability.
Gematik Authenticator in all versions earlier than 4.16.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:NGematik Authenticator
APPGematik< 4.16.0