Medium severity5.3NVD Advisory· Published Aug 13, 2025· Updated Jun 17, 2026
CVE-2025-54791
CVE-2025-54791
Description
OMERO.web provides a web based client and plugin infrastructure. Prior to version 5.29.2, if an error occurred when resetting a user's password using the Forgot Password option in OMERO.web, the error message displayed on the Web page can disclose information about the user. This issue has been patched in version 5.29.2. A workaround involves disabling the Forgot password option in OMERO.web using the omero.web.show_forgot_password configuration property.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
omero-webPyPI | < 5.29.2 | 5.29.2 |
Affected products
3Patches
Vulnerability mechanics
References
4- github.com/ome/omero-web/commit/8aa2789e8f759c73f1517abe9a0abd44e86644adnvdPatchWEB
- github.com/advisories/GHSA-gpmg-4x4g-mr5rghsaADVISORY
- github.com/ome/omero-web/security/advisories/GHSA-gpmg-4x4g-mr5rnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2025-54791ghsaADVISORY
News mentions
0No linked articles in our index yet.