The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Prior to 2.1.0, OIDC-authenticated sessions had no configured maximum inactivity timeout. Sessions persisted indefinitely after login, even after the OIDC access token expired. This vulnerability is fixed in 2.1.0.
Metrics
Affected Vendors & Products
References
History
Wed, 22 Apr 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 22 Apr 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Datasharingframework
Datasharingframework dsf Dev.dsf Dev.dsf dsf-bpe-server Dev.dsf dsf-common-jetty Dev.dsf dsf-fhir-server |
|
| Vendors & Products |
Datasharingframework
Datasharingframework dsf Dev.dsf Dev.dsf dsf-bpe-server Dev.dsf dsf-common-jetty Dev.dsf dsf-fhir-server |
Wed, 22 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Prior to 2.1.0, OIDC-authenticated sessions had no configured maximum inactivity timeout. Sessions persisted indefinitely after login, even after the OIDC access token expired. This vulnerability is fixed in 2.1.0. | |
| Title | DSF: Missing Session Timeout for OIDC Sessions | |
| Weaknesses | CWE-613 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-04-21T21:07:10.503Z
Updated: 2026-04-22T17:44:03.707Z
Reserved: 2026-04-15T20:40:15.518Z
Link: CVE-2026-40939
Updated: 2026-04-22T17:43:59.508Z
Status : Awaiting Analysis
Published: 2026-04-21T22:16:19.547
Modified: 2026-04-22T21:23:52.620
Link: CVE-2026-40939
No data.