Vulnerabilities
Vulnerable Software
Openmicroscopy:  Security Vulnerabilities
OMERO.web provides a web based client and plugin infrastructure. Prior to version 5.29.2, if an error occurred when resetting a user's password using the Forgot Password option in OMERO.web, the error message displayed on the Web page can disclose information about the user. This issue has been patched in version 5.29.2. A workaround involves disabling the Forgot password option in OMERO.web using the omero.web.show_forgot_password configuration property.
CVSS Score
5.3
EPSS Score
0.001
Published
2025-08-13
OMERO.web provides a web based client and plugin infrastructure. There is currently no escaping or validation of the `callback` parameter that can be passed to various OMERO.web endpoints that have JSONP enabled. This vulnerability has been patched in version 5.26.0.
CVSS Score
6.1
EPSS Score
0.004
Published
2024-05-21
OMERO.web provides a web based client and plugin infrastructure. In versions prior to 5.11.0, a variety of templates do not perform proper sanitization through HTML escaping. Due to the lack of sanitization and use of ``jQuery.html()``, there are a whole host of cross-site scripting possibilities with specially crafted input to a variety of fields. This issue is patched in version 5.11.0. There are no known workarounds aside from upgrading.
CVSS Score
9.8
EPSS Score
0.006
Published
2021-10-14
OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 loads various information about the current user such as their id, name and the groups they are in, and these are available on the main webclient pages. This represents an information exposure vulnerability. Some additional information being loaded is not used by the webclient and is being removed in this release. This is fixed in version 5.9.0.
CVSS Score
6.4
EPSS Score
0.004
Published
2021-03-23
OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 supports redirection to a given URL after performing login or switching the group context. These URLs are not validated, allowing redirection to untrusted sites. OMERO.web 5.9.0 adds URL validation before redirecting. External URLs are not considered valid, unless specified in the omero.web.redirect_allowed_hosts setting.
CVSS Score
4.8
EPSS Score
0.003
Published
2021-03-23
OMERO.server before 5.6.1 allows attackers to bypass the security filters and access hidden objects via a crafted query.
CVSS Score
9.8
EPSS Score
0.005
Published
2020-07-22
OMERO before 5.6.1 makes the details of each user available to all users.
CVSS Score
5.3
EPSS Score
0.002
Published
2020-06-17
In ome.services.graphs.GraphTraversal.findObjectDetails in Open Microscopy Environment OMERO.server 5.1.0 through 5.6.0, permissions on OMERO model objects may be circumvented during certain operations such as move and delete, because group permissions are mishandled.
CVSS Score
7.5
EPSS Score
0.001
Published
2020-06-17
In Open Microscopy Environment OMERO.server 5.0.0 through 5.6.0, the reading of files from imported image filesets may circumvent OMERO permissions restrictions. This occurs because the Bio-Formats feature allows an image file to have embedded pathnames.
CVSS Score
7.5
EPSS Score
0.002
Published
2020-06-17
In OMERO before 5.6.1, group owners can access members' data in other groups.
CVSS Score
3.8
EPSS Score
0.002
Published
2020-06-17


Contact Us

Shodan ® - All rights reserved