PT-2021-14458 · Omero.Web · Omero.Web

Jburel

·

Published

2021-03-23

·

Updated

2021-03-27

·

CVE-2021-21376

CVSS v4.0

7.4

High

VectorAV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OMERO.web versions prior to 5.9.0
Description OMERO.web is open source Django-based software for managing microscopy imaging. It loads various information about the current user, such as their id, name, and the groups they are in, which is available on the main webclient pages. This represents an information exposure issue. Some additional information being loaded is not used by the webclient and is being removed.
Recommendations For versions prior to 5.9.0, update to version 5.9.0 to resolve the issue. As a temporary workaround, consider restricting access to sensitive user information until the update is applied.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-21376
GHSA-GFP2-W5JM-955Q
PYSEC-2021-31

Affected Products

Omero.Web