Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gfp2-w5jm-955q

Опубликовано: 23 мар. 2021
Источник: github
Github: Прошло ревью
CVSS4: 7.4
CVSS3: 6.4

Описание

OMERO.web exposes some unnecessary session information in the page

Background

OMERO.web loads various information about the current user such as their id, name and the groups they are in, and these are available on the main webclient pages. Some additional information being loaded is not used by the webclient and is being removed in this release.

Impact

OMERO.web before 5.9.0

Patches

5.9.0

Workarounds

No workaround

References

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

omero-web

pip
Затронутые версииВерсия исправления

< 5.9.0

5.9.0

EPSS

Процентиль: 62%
0.00424
Низкий

7.4 High

CVSS4

6.4 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 6.4
nvd
почти 5 лет назад

OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 loads various information about the current user such as their id, name and the groups they are in, and these are available on the main webclient pages. This represents an information exposure vulnerability. Some additional information being loaded is not used by the webclient and is being removed in this release. This is fixed in version 5.9.0.

EPSS

Процентиль: 62%
0.00424
Низкий

7.4 High

CVSS4

6.4 Medium

CVSS3

Дефекты

CWE-200