VYPR

OMERO.server

by Openmicroscopy

CVEs (3)

  • CVE-2019-16244CriJul 22, 2020
    risk 0.64cvss 9.8epss 0.01

    OMERO.server before 5.6.1 allows attackers to bypass the security filters and access hidden objects via a crafted query.

  • CVE-2019-9944HigJun 17, 2020
    risk 0.49cvss 7.5epss 0.01

    In Open Microscopy Environment OMERO.server 5.0.0 through 5.6.0, the reading of files from imported image filesets may circumvent OMERO permissions restrictions. This occurs because the Bio-Formats feature allows an image file to have embedded pathnames.

  • CVE-2019-9943HigJun 17, 2020
    risk 0.49cvss 7.5epss 0.01

    In ome.services.graphs.GraphTraversal.findObjectDetails in Open Microscopy Environment OMERO.server 5.1.0 through 5.6.0, permissions on OMERO model objects may be circumvented during certain operations such as move and delete, because group permissions are mishandled.