CVE-2021-21376Medium· 6.4▾ SunlitOMERO.web exposes some unnecessary session information in the page
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.2 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.5%
OMERO.web loads various information about the current user such as their id, name and the groups they are in, and these are available on the main webclient pages. Some additional information being loaded is not used by the webclient and is being removed in this release.
OMERO.web before 5.9.0
5.9.0
No workaround
If you have any questions or comments about this advisory:
omero-web < 5.9.0Upgrade to a patched release:
omero-web 5.9.0Connected by shared product, vendor, weakness, or advisory.
CVE-2021-21377Medium· 4.8OMERO webclient does not validate URL redirects on login or switching group.
CVE-2024-35180Medium· 6.1OMERO.web must check that the JSONP callback is a valid function
CVE-2025-54791Medium· 5.3OMERO.web displays unecessary user information when requesting password reset
CVE-2021-41132Critical· 9.8Inconsistent input sanitisation leads to XSS vectors