CVE-2019-9943

In ome.services.graphs.GraphTraversal.findObjectDetails in Open Microscopy Environment OMERO.server 5.1.0 through 5.6.0, permissions on OMERO model objects may be circumvented during certain operations such as move and delete, because group permissions are mishandled.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:openmicroscopy:omero.server:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2020-06-17 17:15

Updated : 2024-02-28 17:47


NVD link : CVE-2019-9943

Mitre link : CVE-2019-9943

CVE.ORG link : CVE-2019-9943


JSON object : View

Products Affected

openmicroscopy

  • omero.server
CWE
CWE-276

Incorrect Default Permissions