Vulnerabilities
Vulnerable Software
OMERO.server before 5.6.1 allows attackers to bypass the security filters and access hidden objects via a crafted query.
CVSS Score
9.8
EPSS Score
0.005
Published
2020-07-22
In ome.services.graphs.GraphTraversal.findObjectDetails in Open Microscopy Environment OMERO.server 5.1.0 through 5.6.0, permissions on OMERO model objects may be circumvented during certain operations such as move and delete, because group permissions are mishandled.
CVSS Score
7.5
EPSS Score
0.001
Published
2020-06-17
In Open Microscopy Environment OMERO.server 5.0.0 through 5.6.0, the reading of files from imported image filesets may circumvent OMERO permissions restrictions. This occurs because the Bio-Formats feature allows an image file to have embedded pathnames.
CVSS Score
7.5
EPSS Score
0.002
Published
2020-06-17


Contact Us

Shodan ® - All rights reserved