GHSA-jhrq-7mrq-96j8 ("Additional JSONP callbacks")

Affects OMERO.web <=5.33.0

back to Advisories

Synopsis

Additional JSONP callbacks

Background

Following CVE-2024-35180, there are still occurrences of missing escaping and validation of the callback parameter that can be passed to various OMERO.web endpoints that have JSONP enabled. It is quite difficult or even impossible to exploit this in vanilla OMERO.web. However, these metadata endpoints are likely to be used by third-party plugins.

Affected Packages

OMERO.web <=5.33.0

Impact

Moderate severity.

Resolution

All OMERO.web deployments should be upgraded to at least 5.33.1.

Thanks

Arpit Jain for notifying the OME team of this security issue via security@openmicroscopy.org.


back to top