GHSA-g4rf-pc26-6hmr

Suggest an improvement
Source
https://github.com/advisories/GHSA-g4rf-pc26-6hmr
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/03/GHSA-g4rf-pc26-6hmr/GHSA-g4rf-pc26-6hmr.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-g4rf-pc26-6hmr
Aliases
Related
Published
2021-03-23T15:26:49Z
Modified
2024-10-08T13:05:07.812376Z
Severity
  • 4.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
  • 5.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
OMERO webclient does not validate URL redirects on login or switching group.
Details

Background

OMERO.web supports redirection to a given URL after performing login or switching the group context. These URLs are not validated, allowing redirection to untrusted sites. OMERO.web 5.9.0 adds URL validation before redirecting. External URLs are not considered valid, unless specified in the omero.web.redirect_allowed_hosts setting.

Impact

OMERO.web before 5.9.0

Patches

5.9.0

Workarounds

No workaround

References

For more information

If you have any questions or comments about this advisory: * Open an issue in omero-web * Email us at security

Database specific
{
    "nvd_published_at": "2021-03-23T16:15:00Z",
    "cwe_ids": [
        "CWE-601"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2021-03-23T15:25:55Z"
}
References

Affected packages

PyPI / omero-web

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.9.0

Affected versions

5.*

5.5.dev1
5.5.dev2
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.6.0
5.6.1
5.6.2
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1