PT-2021-14458 · Omero.Web · Omero.Web
Jburel
·
Published
2021-03-23
·
Updated
2021-03-27
·
CVE-2021-21376
CVSS v4.0
7.4
High
| Vector | AV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OMERO.web versions prior to 5.9.0
Description
OMERO.web is open source Django-based software for managing microscopy imaging. It loads various information about the current user, such as their
id, name, and the groups they are in, which is available on the main webclient pages. This represents an information exposure issue. Some additional information being loaded is not used by the webclient and is being removed.Recommendations
For versions prior to 5.9.0, update to version 5.9.0 to resolve the issue. As a temporary workaround, consider restricting access to sensitive user information until the update is applied.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Omero.Web