ZeroHour

CVE-2017-1000438

CVSS 3.0
8.3 high
EPSS
<1%p59
Published
()
Modified
Description

In OMERO 5.3.3 or earlier a user could create an OriginalFile and adjust its path such that it now points to another user's file on the underlying filesystem, then manipulate the user's data.

Vendors
openmicroscopy
Products
omero
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

In the news

No ingested article mentions this CVE yet.