In ome.services.graphs.GraphTraversal.findObjectDetails in Open Microscopy Environment OMERO.server 5.1.0 through 5.6.0, permissions on OMERO model objects may be circumvented during certain operations such as move and delete, because group permissions are mishandled.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NOpenmicroscopy Omero.server
APPOpenmicroscopy5.1.0 – 5.6.0
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Powiązane podatności
CVE-2019-16244CRITICAL9.8PL ✓ten sam produkt
OMERO.server — obejście filtrów bezpieczeństwa i dostęp do ukrytych obiektów
CVE-2019-9944HIGH7.5ten sam produkt
In Open Microscopy Environment OMERO.server 5.0.0 through 5.6.0, the reading of files from imported image file...
CVE-2021-41132CRITICAL9.8PL ✓ten sam vendor
XSS w OMERO.web — brak sanityzacji HTML w szablonach
CVE-2014-7198HIGH8.8ten sam vendor
OMERO before 5.0.6 has multiple CSRF vulnerabilities because the framework for OMERO's web interface lacks CSR...
CVE-2018-1000633HIGH7.2ten sam vendor
The Open Microscopy Environment OMERO.web version prior to 5.4.7 contains an Information Exposure Through Log ...