Affects OMERO.web <=5.33.0
Additional JSONP callbacks
Following CVE-2024-35180, there are still occurrences of missing escaping and validation of the callback parameter that can be passed to various OMERO.web endpoints that have JSONP enabled. It is quite difficult or even impossible to exploit this in vanilla OMERO.web. However, these metadata endpoints are likely to be used by third-party plugins.
OMERO.web <=5.33.0
Moderate severity.
All OMERO.web deployments should be upgraded to at least 5.33.1.
Arpit Jain for notifying the OME team of this security issue via security@openmicroscopy.org.