In ome.services.graphs.GraphTraversal.findObjectDetails in Open Microscopy Environment OMERO.server 5.1.0 through 5.6.0, permissions on OMERO model objects may be circumvented during certain operations such as move and delete, because group permissions are mishandled.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NOpenmicroscopy Omero.server
APPOpenmicroscopy5.1.0 – 5.6.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2019-16244CRITICAL9.8PL ✓same product
OMERO.server — obejście filtrów bezpieczeństwa i dostęp do ukrytych obiektów
CVE-2019-9944HIGH7.5same product
In Open Microscopy Environment OMERO.server 5.0.0 through 5.6.0, the reading of files from imported image file...
CVE-2021-41132CRITICAL9.8PL ✓same vendor
XSS w OMERO.web — brak sanityzacji HTML w szablonach
CVE-2014-7198HIGH8.8same vendor
OMERO before 5.0.6 has multiple CSRF vulnerabilities because the framework for OMERO's web interface lacks CSR...
CVE-2018-1000633HIGH7.2same vendor
The Open Microscopy Environment OMERO.web version prior to 5.4.7 contains an Information Exposure Through Log ...