CVE-2019-9943

In ome.services.graphs.GraphTraversal.findObjectDetails in Open Microscopy Environment OMERO.server 5.1.0 through 5.6.0, permissions on OMERO model objects may be circumvented during certain operations such as move and delete, because group permissions are mishandled.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openmicroscopy:omero.server:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:52

Type Values Removed Values Added
References () https://www.openmicroscopy.org/security/advisories/2019-SV2/ - Vendor Advisory () https://www.openmicroscopy.org/security/advisories/2019-SV2/ - Vendor Advisory

Information

Published : 2020-06-17 17:15

Updated : 2024-11-21 04:52


NVD link : CVE-2019-9943

Mitre link : CVE-2019-9943

CVE.ORG link : CVE-2019-9943


JSON object : View

Products Affected

openmicroscopy

  • omero.server
CWE
CWE-276

Incorrect Default Permissions