CVE-2020-7932
Summary
| CVE | CVE-2020-7932 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-06-17 17:15:00 UTC |
| Updated | 2020-06-24 15:12:00 UTC |
| Description | OMERO.web before 5.6.3 optionally allows sensitive data elements (e.g., a session key) to be passed as URL query parameters. If an attacker tricks a user into clicking a malicious link in OMERO.web, the information in the query parameters may be exposed in the Referer header seen by the target. Information in the URL path such as object IDs may also be exposed. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Openmicroscopy | Omero.web | All | All | All | All |
| Application | Openmicroscopy | Omero.web | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 2019-SV4 Web Referrer Leakage | Open Microscopy Environment (OME) | CONFIRM | www.openmicroscopy.org | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.