OMERO.server before 5.6.1 allows attackers to bypass the security filters and access hidden objects via a crafted query.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpenmicroscopy Omero.server
APPOpenmicroscopy< 5.6.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2019-9943HIGH7.5same product
In ome.services.graphs.GraphTraversal.findObjectDetails in Open Microscopy Environment OMERO.server 5.1.0 thro...
CVE-2019-9944HIGH7.5same product
In Open Microscopy Environment OMERO.server 5.0.0 through 5.6.0, the reading of files from imported image file...
CVE-2021-41132CRITICAL9.8PL ✓same vendor
XSS w OMERO.web — brak sanityzacji HTML w szablonach
CVE-2014-7198HIGH8.8same vendor
OMERO before 5.0.6 has multiple CSRF vulnerabilities because the framework for OMERO's web interface lacks CSR...
CVE-2018-1000633HIGH7.2same vendor
The Open Microscopy Environment OMERO.web version prior to 5.4.7 contains an Information Exposure Through Log ...