Omero
by Ome
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-1000438 | Hig | 0.54 | 8.3 | 0.01 | Jan 2, 2018 | In OMERO 5.3.3 or earlier a user could create an OriginalFile and adjust its path such that it now points to another user's file on the underlying filesystem, then manipulate the user's data. | ||
| CVE-2020-6752 | 0.00 | — | 0.01 | Jun 17, 2020 | In OMERO before 5.6.1, group owners can access members' data in other groups. | |||
| CVE-2019-16245 | 0.00 | — | 0.01 | Jun 17, 2020 | OMERO before 5.6.1 makes the details of each user available to all users. | |||
| CVE-2014-7198 | 0.00 | — | 0.01 | Mar 31, 2019 | OMERO before 5.0.6 has multiple CSRF vulnerabilities because the framework for OMERO's web interface lacks CSRF protection. |
- risk 0.54cvss 8.3epss 0.01
In OMERO 5.3.3 or earlier a user could create an OriginalFile and adjust its path such that it now points to another user's file on the underlying filesystem, then manipulate the user's data.
- CVE-2020-6752Jun 17, 2020risk 0.00cvss —epss 0.01
In OMERO before 5.6.1, group owners can access members' data in other groups.
- CVE-2019-16245Jun 17, 2020risk 0.00cvss —epss 0.01
OMERO before 5.6.1 makes the details of each user available to all users.
- CVE-2014-7198Mar 31, 2019risk 0.00cvss —epss 0.01
OMERO before 5.0.6 has multiple CSRF vulnerabilities because the framework for OMERO's web interface lacks CSRF protection.