VendorsOpen Microscopyomero.weball versions
Vulnerabilities

Open Microscopy Environment OMERO.web

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2021-21376
Information Exposure in OMERO.web
Published 2021-03-23 · Modified
6.5EPSS 0.015
CVE-2020-7932
OMERO.web before 5.6.3 optionally allows sensitive data elements (e.g., a session key) to be passed as URL query parameters. If an attacker tricks a user into clicking a malicious link in OMERO.web, the information in the query parameters may be exposed in the Referer header seen by the target. Information in the URL path such as object IDs may also be exposed.
Published 2020-06-17 · Modified
5.7EPSS 0.008
CVE-2021-21377
Open Redirect in OMERO.web
Published 2021-03-23 · Modified
5.4EPSS 0.008