Skip to content

OMERO.web exposes some unnecessary session information in the page

Moderate severity GitHub Reviewed Published Mar 17, 2021 in ome/omero-web • Updated Feb 1, 2023

Package

pip omero-web (pip)

Affected versions

< 5.9.0

Patched versions

5.9.0

Description

Background

OMERO.web loads various information about the current user such as their id, name and the groups they are in, and these are available on the main webclient pages. Some additional information being loaded is not used by the webclient and is being removed in this release.

Impact

OMERO.web before 5.9.0

Patches

5.9.0

Workarounds

No workaround

References

For more information

If you have any questions or comments about this advisory:

References

@jburel jburel published to ome/omero-web Mar 17, 2021
Reviewed Mar 23, 2021
Published to the GitHub Advisory Database Mar 23, 2021
Published by the National Vulnerability Database Mar 23, 2021
Last updated Feb 1, 2023

Severity

Moderate

EPSS score

0.091%
(39th percentile)

Weaknesses

CVE ID

CVE-2021-21376

GHSA ID

GHSA-gfp2-w5jm-955q

Source code

No known source code
Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.