CVE-2021-21377Medium· 4.8▾ SunlitOMERO webclient does not validate URL redirects on login or switching group.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 26.4 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.8%
OMERO.web supports redirection to a given URL after performing login or switching the group context. These URLs are not validated, allowing redirection to untrusted sites. OMERO.web 5.9.0 adds URL validation before redirecting. External URLs are not considered valid, unless specified in the omero.web.redirect_allowed_hosts setting.
OMERO.web before 5.9.0
5.9.0
No workaround
If you have any questions or comments about this advisory:
omero-web < 5.9.0Upgrade to a patched release:
omero-web 5.9.0Connected by shared product, vendor, weakness, or advisory.
CVE-2021-21376Medium· 6.4OMERO.web exposes some unnecessary session information in the page
CVE-2024-35180Medium· 6.1OMERO.web must check that the JSONP callback is a valid function
CVE-2025-54791Medium· 5.3OMERO.web displays unecessary user information when requesting password reset
CVE-2021-41132Critical· 9.8Inconsistent input sanitisation leads to XSS vectors