Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g4rf-pc26-6hmr

Опубликовано: 23 мар. 2021
Источник: github
Github: Прошло ревью
CVSS4: 5.9
CVSS3: 4.8

Описание

OMERO webclient does not validate URL redirects on login or switching group.

Background

OMERO.web supports redirection to a given URL after performing login or switching the group context. These URLs are not validated, allowing redirection to untrusted sites. OMERO.web 5.9.0 adds URL validation before redirecting. External URLs are not considered valid, unless specified in the omero.web.redirect_allowed_hosts setting.

Impact

OMERO.web before 5.9.0

Patches

5.9.0

Workarounds

No workaround

References

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

omero-web

pip
Затронутые версииВерсия исправления

< 5.9.0

5.9.0

EPSS

Процентиль: 54%
0.00314
Низкий

5.9 Medium

CVSS4

4.8 Medium

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 4.8
nvd
почти 5 лет назад

OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 supports redirection to a given URL after performing login or switching the group context. These URLs are not validated, allowing redirection to untrusted sites. OMERO.web 5.9.0 adds URL validation before redirecting. External URLs are not considered valid, unless specified in the omero.web.redirect_allowed_hosts setting.

EPSS

Процентиль: 54%
0.00314
Низкий

5.9 Medium

CVSS4

4.8 Medium

CVSS3

Дефекты

CWE-601