PT-2020-11367 · Open Microscopy Environment · Omero.Server
Published
2020-06-17
·
Updated
2020-06-24
·
CVE-2019-9943
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Open Microscopy Environment OMERO.server versions 5.1.0 through 5.6.0
Description
The issue concerns the mishandling of group permissions in the
ome.services.graphs.GraphTraversal.findObjectDetails function, which can lead to the circumvention of permissions on OMERO model objects during operations like move and delete.Recommendations
For Open Microscopy Environment OMERO.server versions 5.1.0 through 5.6.0, consider restricting access to the
findObjectDetails function in ome.services.graphs.GraphTraversal until a patch is available to properly handle group permissions.Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Omero.Server