Vulnerabilites related to openmicroscopy - omero.web
CVE-2021-21377 (GCVE-0-2021-21377)
Vulnerability from cvelistv5
Published
2021-03-23 15:25
Modified
2024-08-03 18:09
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-601 - URL Redirection to Untrusted Site ('Open Redirect')
Summary
OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 supports redirection to a given URL after performing login or switching the group context. These URLs are not validated, allowing redirection to untrusted sites. OMERO.web 5.9.0 adds URL validation before redirecting. External URLs are not considered valid, unless specified in the omero.web.redirect_allowed_hosts setting.
References
► | URL | Tags | |||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-03T18:09:15.795Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://pypi.org/project/omero-web/" }, { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://github.com/ome/omero-web/blob/master/CHANGELOG.md#590-march-2021" }, { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://github.com/ome/omero-web/commit/952f8e5d28532fbb14fb665982211329d137908c" }, { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "https://github.com/ome/omero-web/security/advisories/GHSA-g4rf-pc26-6hmr" }, { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://www.openmicroscopy.org/security/advisories/2021-SV2/" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "omero-web", "vendor": "ome", "versions": [ { "status": "affected", "version": "\u003c 5.9.0" } ] } ], "descriptions": [ { "lang": "en", "value": "OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 supports redirection to a given URL after performing login or switching the group context. These URLs are not validated, allowing redirection to untrusted sites. OMERO.web 5.9.0 adds URL validation before redirecting. External URLs are not considered valid, unless specified in the omero.web.redirect_allowed_hosts setting." } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 4.8, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N", "version": "3.1" } } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-601", "description": "CWE-601 URL Redirection to Untrusted Site (\u0027Open Redirect\u0027)", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2021-03-23T15:25:28", "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa", "shortName": "GitHub_M" }, "references": [ { "tags": [ "x_refsource_MISC" ], "url": "https://pypi.org/project/omero-web/" }, { "tags": [ "x_refsource_MISC" ], "url": "https://github.com/ome/omero-web/blob/master/CHANGELOG.md#590-march-2021" }, { "tags": [ "x_refsource_MISC" ], "url": "https://github.com/ome/omero-web/commit/952f8e5d28532fbb14fb665982211329d137908c" }, { "tags": [ "x_refsource_CONFIRM" ], "url": "https://github.com/ome/omero-web/security/advisories/GHSA-g4rf-pc26-6hmr" }, { "tags": [ "x_refsource_MISC" ], "url": "https://www.openmicroscopy.org/security/advisories/2021-SV2/" } ], "source": { "advisory": "GHSA-g4rf-pc26-6hmr", "discovery": "UNKNOWN" }, "title": "Open Redirect in OMERO.web", "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "security-advisories@github.com", "ID": "CVE-2021-21377", "STATE": "PUBLIC", "TITLE": "Open Redirect in OMERO.web" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "omero-web", "version": { "version_data": [ { "version_value": "\u003c 5.9.0" } ] } } ] }, "vendor_name": "ome" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 supports redirection to a given URL after performing login or switching the group context. These URLs are not validated, allowing redirection to untrusted sites. OMERO.web 5.9.0 adds URL validation before redirecting. External URLs are not considered valid, unless specified in the omero.web.redirect_allowed_hosts setting." } ] }, "impact": { "cvss": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 4.8, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N", "version": "3.1" } }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "CWE-601 URL Redirection to Untrusted Site (\u0027Open Redirect\u0027)" } ] } ] }, "references": { "reference_data": [ { "name": "https://pypi.org/project/omero-web/", "refsource": "MISC", "url": "https://pypi.org/project/omero-web/" }, { "name": "https://github.com/ome/omero-web/blob/master/CHANGELOG.md#590-march-2021", "refsource": "MISC", "url": "https://github.com/ome/omero-web/blob/master/CHANGELOG.md#590-march-2021" }, { "name": "https://github.com/ome/omero-web/commit/952f8e5d28532fbb14fb665982211329d137908c", "refsource": "MISC", "url": "https://github.com/ome/omero-web/commit/952f8e5d28532fbb14fb665982211329d137908c" }, { "name": "https://github.com/ome/omero-web/security/advisories/GHSA-g4rf-pc26-6hmr", "refsource": "CONFIRM", "url": "https://github.com/ome/omero-web/security/advisories/GHSA-g4rf-pc26-6hmr" }, { "name": "https://www.openmicroscopy.org/security/advisories/2021-SV2/", "refsource": "MISC", "url": "https://www.openmicroscopy.org/security/advisories/2021-SV2/" } ] }, "source": { "advisory": "GHSA-g4rf-pc26-6hmr", "discovery": "UNKNOWN" } } } }, "cveMetadata": { "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa", "assignerShortName": "GitHub_M", "cveId": "CVE-2021-21377", "datePublished": "2021-03-23T15:25:28", "dateReserved": "2020-12-22T00:00:00", "dateUpdated": "2024-08-03T18:09:15.795Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2020-7932 (GCVE-0-2020-7932)
Vulnerability from cvelistv5
Published
2020-06-17 16:15
Modified
2024-08-04 09:48
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- n/a
Summary
OMERO.web before 5.6.3 optionally allows sensitive data elements (e.g., a session key) to be passed as URL query parameters. If an attacker tricks a user into clicking a malicious link in OMERO.web, the information in the query parameters may be exposed in the Referer header seen by the target. Information in the URL path such as object IDs may also be exposed.
References
► | URL | Tags | |||
---|---|---|---|---|---|
|
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-04T09:48:24.479Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "https://www.openmicroscopy.org/security/advisories/2019-SV4/" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "n/a", "vendor": "n/a", "versions": [ { "status": "affected", "version": "n/a" } ] } ], "datePublic": "2020-03-25T00:00:00", "descriptions": [ { "lang": "en", "value": "OMERO.web before 5.6.3 optionally allows sensitive data elements (e.g., a session key) to be passed as URL query parameters. If an attacker tricks a user into clicking a malicious link in OMERO.web, the information in the query parameters may be exposed in the Referer header seen by the target. Information in the URL path such as object IDs may also be exposed." } ], "problemTypes": [ { "descriptions": [ { "description": "n/a", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2020-06-17T16:15:32", "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca", "shortName": "mitre" }, "references": [ { "tags": [ "x_refsource_CONFIRM" ], "url": "https://www.openmicroscopy.org/security/advisories/2019-SV4/" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2020-7932", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "n/a", "version": { "version_data": [ { "version_value": "n/a" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "OMERO.web before 5.6.3 optionally allows sensitive data elements (e.g., a session key) to be passed as URL query parameters. If an attacker tricks a user into clicking a malicious link in OMERO.web, the information in the query parameters may be exposed in the Referer header seen by the target. Information in the URL path such as object IDs may also be exposed." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "n/a" } ] } ] }, "references": { "reference_data": [ { "name": "https://www.openmicroscopy.org/security/advisories/2019-SV4/", "refsource": "CONFIRM", "url": "https://www.openmicroscopy.org/security/advisories/2019-SV4/" } ] } } } }, "cveMetadata": { "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca", "assignerShortName": "mitre", "cveId": "CVE-2020-7932", "datePublished": "2020-06-17T16:15:32", "dateReserved": "2020-01-23T00:00:00", "dateUpdated": "2024-08-04T09:48:24.479Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2021-21376 (GCVE-0-2021-21376)
Vulnerability from cvelistv5
Published
2021-03-23 15:25
Modified
2024-08-03 18:09
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-200 - Information Exposure
Summary
OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 loads various information about the current user such as their id, name and the groups they are in, and these are available on the main webclient pages. This represents an information exposure vulnerability. Some additional information being loaded is not used by the webclient and is being removed in this release. This is fixed in version 5.9.0.
References
► | URL | Tags | |||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-03T18:09:15.994Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "https://github.com/ome/omero-web/security/advisories/GHSA-gfp2-w5jm-955q" }, { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://pypi.org/project/omero-web/" }, { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://github.com/ome/omero-web/blob/master/CHANGELOG.md#590-march-2021" }, { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://www.openmicroscopy.org/security/advisories/2021-SV1/" }, { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://github.com/ome/omero-web/commit/952f8e5d28532fbb14fb665982211329d137908c" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "omero-web", "vendor": "ome", "versions": [ { "status": "affected", "version": "\u003c 5.9.0" } ] } ], "descriptions": [ { "lang": "en", "value": "OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 loads various information about the current user such as their id, name and the groups they are in, and these are available on the main webclient pages. This represents an information exposure vulnerability. Some additional information being loaded is not used by the webclient and is being removed in this release. This is fixed in version 5.9.0." } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 6.4, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N", "version": "3.1" } } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-200", "description": "CWE-200 Information Exposure", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2021-03-23T15:25:22", "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa", "shortName": "GitHub_M" }, "references": [ { "tags": [ "x_refsource_CONFIRM" ], "url": "https://github.com/ome/omero-web/security/advisories/GHSA-gfp2-w5jm-955q" }, { "tags": [ "x_refsource_MISC" ], "url": "https://pypi.org/project/omero-web/" }, { "tags": [ "x_refsource_MISC" ], "url": "https://github.com/ome/omero-web/blob/master/CHANGELOG.md#590-march-2021" }, { "tags": [ "x_refsource_MISC" ], "url": "https://www.openmicroscopy.org/security/advisories/2021-SV1/" }, { "tags": [ "x_refsource_MISC" ], "url": "https://github.com/ome/omero-web/commit/952f8e5d28532fbb14fb665982211329d137908c" } ], "source": { "advisory": "GHSA-gfp2-w5jm-955q", "discovery": "UNKNOWN" }, "title": "Information Exposure in OMERO.web", "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "security-advisories@github.com", "ID": "CVE-2021-21376", "STATE": "PUBLIC", "TITLE": "Information Exposure in OMERO.web" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "omero-web", "version": { "version_data": [ { "version_value": "\u003c 5.9.0" } ] } } ] }, "vendor_name": "ome" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 loads various information about the current user such as their id, name and the groups they are in, and these are available on the main webclient pages. This represents an information exposure vulnerability. Some additional information being loaded is not used by the webclient and is being removed in this release. This is fixed in version 5.9.0." } ] }, "impact": { "cvss": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 6.4, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N", "version": "3.1" } }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "CWE-200 Information Exposure" } ] } ] }, "references": { "reference_data": [ { "name": "https://github.com/ome/omero-web/security/advisories/GHSA-gfp2-w5jm-955q", "refsource": "CONFIRM", "url": "https://github.com/ome/omero-web/security/advisories/GHSA-gfp2-w5jm-955q" }, { "name": "https://pypi.org/project/omero-web/", "refsource": "MISC", "url": "https://pypi.org/project/omero-web/" }, { "name": "https://github.com/ome/omero-web/blob/master/CHANGELOG.md#590-march-2021", "refsource": "MISC", "url": "https://github.com/ome/omero-web/blob/master/CHANGELOG.md#590-march-2021" }, { "name": "https://www.openmicroscopy.org/security/advisories/2021-SV1/", "refsource": "MISC", "url": "https://www.openmicroscopy.org/security/advisories/2021-SV1/" }, { "name": "https://github.com/ome/omero-web/commit/952f8e5d28532fbb14fb665982211329d137908c", "refsource": "MISC", "url": "https://github.com/ome/omero-web/commit/952f8e5d28532fbb14fb665982211329d137908c" } ] }, "source": { "advisory": "GHSA-gfp2-w5jm-955q", "discovery": "UNKNOWN" } } } }, "cveMetadata": { "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa", "assignerShortName": "GitHub_M", "cveId": "CVE-2021-21376", "datePublished": "2021-03-23T15:25:22", "dateReserved": "2020-12-22T00:00:00", "dateUpdated": "2024-08-03T18:09:15.994Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
Vulnerability from fkie_nvd
Published
2021-03-23 16:15
Modified
2024-11-21 05:48
Severity ?
6.4 (Medium) - CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N
6.5 (Medium) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
6.5 (Medium) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Summary
OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 loads various information about the current user such as their id, name and the groups they are in, and these are available on the main webclient pages. This represents an information exposure vulnerability. Some additional information being loaded is not used by the webclient and is being removed in this release. This is fixed in version 5.9.0.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
openmicroscopy | omero.web | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:openmicroscopy:omero.web:*:*:*:*:*:*:*:*", "matchCriteriaId": "FE6BE44A-DB7D-4846-BEBE-9C96D2294B94", "versionEndExcluding": "5.9.0", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 loads various information about the current user such as their id, name and the groups they are in, and these are available on the main webclient pages. This represents an information exposure vulnerability. Some additional information being loaded is not used by the webclient and is being removed in this release. This is fixed in version 5.9.0." }, { "lang": "es", "value": "OMERO.web es un software de c\u00f3digo abierto basado en Django para administrar im\u00e1genes microsc\u00f3picas.\u0026#xa0;OMERO.web versiones anteriores a 5.9.0 carga diversa informaci\u00f3n sobre el usuario actual, como su identificaci\u00f3n, nombre y los grupos en los que se encuentra, y estos est\u00e1n disponibles en las p\u00e1ginas principales del cliente web.\u0026#xa0;Esto representa una vulnerabilidad de exposici\u00f3n de la informaci\u00f3n.\u0026#xa0;Parte de la informaci\u00f3n adicional que se est\u00e1 cargando no es usada por el cliente web y se eliminar\u00e1 en esta versi\u00f3n.\u0026#xa0;Esto es corregido en versi\u00f3n 5.9.0" } ], "id": "CVE-2021-21376", "lastModified": "2024-11-21T05:48:13.773", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": { "accessComplexity": "LOW", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "NONE", "baseScore": 5.0, "confidentialityImpact": "PARTIAL", "integrityImpact": "NONE", "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N", "version": "2.0" }, "exploitabilityScore": 10.0, "impactScore": 2.9, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": false } ], "cvssMetricV31": [ { "cvssData": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 6.4, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N", "version": "3.1" }, "exploitabilityScore": 1.2, "impactScore": 5.2, "source": "security-advisories@github.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "version": "3.1" }, "exploitabilityScore": 2.8, "impactScore": 3.6, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2021-03-23T16:15:14.173", "references": [ { "source": "security-advisories@github.com", "tags": [ "Release Notes", "Third Party Advisory" ], "url": "https://github.com/ome/omero-web/blob/master/CHANGELOG.md#590-march-2021" }, { "source": "security-advisories@github.com", "tags": [ "Patch", "Third Party Advisory" ], "url": "https://github.com/ome/omero-web/commit/952f8e5d28532fbb14fb665982211329d137908c" }, { "source": "security-advisories@github.com", "tags": [ "Third Party Advisory" ], "url": "https://github.com/ome/omero-web/security/advisories/GHSA-gfp2-w5jm-955q" }, { "source": "security-advisories@github.com", "tags": [ "Release Notes", "Third Party Advisory" ], "url": "https://pypi.org/project/omero-web/" }, { "source": "security-advisories@github.com", "tags": [ "Vendor Advisory" ], "url": "https://www.openmicroscopy.org/security/advisories/2021-SV1/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Release Notes", "Third Party Advisory" ], "url": "https://github.com/ome/omero-web/blob/master/CHANGELOG.md#590-march-2021" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Patch", "Third Party Advisory" ], "url": "https://github.com/ome/omero-web/commit/952f8e5d28532fbb14fb665982211329d137908c" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory" ], "url": "https://github.com/ome/omero-web/security/advisories/GHSA-gfp2-w5jm-955q" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Release Notes", "Third Party Advisory" ], "url": "https://pypi.org/project/omero-web/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.openmicroscopy.org/security/advisories/2021-SV1/" } ], "sourceIdentifier": "security-advisories@github.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-200" } ], "source": "security-advisories@github.com", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2021-03-23 16:15
Modified
2024-11-21 05:48
Severity ?
4.8 (Medium) - CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
5.4 (Medium) - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
5.4 (Medium) - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Summary
OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 supports redirection to a given URL after performing login or switching the group context. These URLs are not validated, allowing redirection to untrusted sites. OMERO.web 5.9.0 adds URL validation before redirecting. External URLs are not considered valid, unless specified in the omero.web.redirect_allowed_hosts setting.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
openmicroscopy | omero.web | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:openmicroscopy:omero.web:*:*:*:*:*:*:*:*", "matchCriteriaId": "FE6BE44A-DB7D-4846-BEBE-9C96D2294B94", "versionEndExcluding": "5.9.0", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 supports redirection to a given URL after performing login or switching the group context. These URLs are not validated, allowing redirection to untrusted sites. OMERO.web 5.9.0 adds URL validation before redirecting. External URLs are not considered valid, unless specified in the omero.web.redirect_allowed_hosts setting." }, { "lang": "es", "value": "OMERO.web es un software de c\u00f3digo abierto basado en Django para administrar im\u00e1genes microsc\u00f3picas.\u0026#xa0;OMERO.web versiones anteriores a 5.9.0 admite el redireccionamiento a una URL determinada despu\u00e9s de iniciar sesi\u00f3n o cambiar el contexto del grupo.\u0026#xa0;Estas URL no est\u00e1n comprobadas, permitiendo un redireccionamiento a sitios que no son confiables.\u0026#xa0;OMERO.web versi\u00f3n 5.9.0 agrega comprobaci\u00f3n de URL antes de redireccionar.\u0026#xa0;Las URL Externas no se consideran v\u00e1lidas, a menos que se especifiquen en la configuraci\u00f3n omero.web.redirect_allowed_hosts" } ], "id": "CVE-2021-21377", "lastModified": "2024-11-21T05:48:13.900", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "SINGLE", "availabilityImpact": "NONE", "baseScore": 4.9, "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:S/C:P/I:P/A:N", "version": "2.0" }, "exploitabilityScore": 6.8, "impactScore": 4.9, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": true } ], "cvssMetricV31": [ { "cvssData": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 4.8, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N", "version": "3.1" }, "exploitabilityScore": 1.2, "impactScore": 3.6, "source": "security-advisories@github.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 5.4, "baseSeverity": "MEDIUM", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "privilegesRequired": "LOW", "scope": "CHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N", "version": "3.1" }, "exploitabilityScore": 2.3, "impactScore": 2.7, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2021-03-23T16:15:14.283", "references": [ { "source": "security-advisories@github.com", "tags": [ "Release Notes", "Third Party Advisory" ], "url": "https://github.com/ome/omero-web/blob/master/CHANGELOG.md#590-march-2021" }, { "source": "security-advisories@github.com", "tags": [ "Patch", "Third Party Advisory" ], "url": "https://github.com/ome/omero-web/commit/952f8e5d28532fbb14fb665982211329d137908c" }, { "source": "security-advisories@github.com", "tags": [ "Third Party Advisory" ], "url": "https://github.com/ome/omero-web/security/advisories/GHSA-g4rf-pc26-6hmr" }, { "source": "security-advisories@github.com", "tags": [ "Third Party Advisory" ], "url": "https://pypi.org/project/omero-web/" }, { "source": "security-advisories@github.com", "tags": [ "Vendor Advisory" ], "url": "https://www.openmicroscopy.org/security/advisories/2021-SV2/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Release Notes", "Third Party Advisory" ], "url": "https://github.com/ome/omero-web/blob/master/CHANGELOG.md#590-march-2021" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Patch", "Third Party Advisory" ], "url": "https://github.com/ome/omero-web/commit/952f8e5d28532fbb14fb665982211329d137908c" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory" ], "url": "https://github.com/ome/omero-web/security/advisories/GHSA-g4rf-pc26-6hmr" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory" ], "url": "https://pypi.org/project/omero-web/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.openmicroscopy.org/security/advisories/2021-SV2/" } ], "sourceIdentifier": "security-advisories@github.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-601" } ], "source": "security-advisories@github.com", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2020-06-17 17:15
Modified
2024-11-21 05:38
Severity ?
Summary
OMERO.web before 5.6.3 optionally allows sensitive data elements (e.g., a session key) to be passed as URL query parameters. If an attacker tricks a user into clicking a malicious link in OMERO.web, the information in the query parameters may be exposed in the Referer header seen by the target. Information in the URL path such as object IDs may also be exposed.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
openmicroscopy | omero.web | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:openmicroscopy:omero.web:*:*:*:*:*:*:*:*", "matchCriteriaId": "8AC9EF6D-87D6-42C9-864B-3B8C06FAE6E4", "versionEndExcluding": "5.6.3", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "OMERO.web before 5.6.3 optionally allows sensitive data elements (e.g., a session key) to be passed as URL query parameters. If an attacker tricks a user into clicking a malicious link in OMERO.web, the information in the query parameters may be exposed in the Referer header seen by the target. Information in the URL path such as object IDs may also be exposed." }, { "lang": "es", "value": "OMERO.web versiones anteriores a 5.6.3, opcionalmente permite que los elementos de datos confidenciales (por ejemplo, una clave de sesi\u00f3n) sean pasados como par\u00e1metros de consulta de URL. Si un atacante enga\u00f1a a un usuario para que haga clic en un enlace malicioso en OMERO.web, la informaci\u00f3n en los par\u00e1metros de consulta puede exponerse en el encabezado Referer visto por el objetivo. Tambi\u00e9n puede ser expuesta informaci\u00f3n en la ruta de la URL, tales como los ID de los objetos" } ], "id": "CVE-2020-7932", "lastModified": "2024-11-21T05:38:02.157", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "LOW", "cvssData": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "SINGLE", "availabilityImpact": "NONE", "baseScore": 3.5, "confidentialityImpact": "PARTIAL", "integrityImpact": "NONE", "vectorString": "AV:N/AC:M/Au:S/C:P/I:N/A:N", "version": "2.0" }, "exploitabilityScore": 6.8, "impactScore": 2.9, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": true } ], "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 5.7, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N", "version": "3.1" }, "exploitabilityScore": 2.1, "impactScore": 3.6, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2020-06-17T17:15:10.753", "references": [ { "source": "cve@mitre.org", "tags": [ "Vendor Advisory" ], "url": "https://www.openmicroscopy.org/security/advisories/2019-SV4/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.openmicroscopy.org/security/advisories/2019-SV4/" } ], "sourceIdentifier": "cve@mitre.org", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-200" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }