CVE-2019-9943

In ome.services.graphs.GraphTraversal.findObjectDetails in Open Microscopy Environment OMERO.server 5.1.0 through 5.6.0, permissions on OMERO model objects may be circumvented during certain operations such as move and delete, because group permissions are mishandled.
References
Configurations

Configuration 1

cpe:2.3:a:openmicroscopy:omero.server:*:*:*:*:*:*:*:*

Information

Published : 2020-06-17 05:15

Updated : 2020-06-24 02:57


NVD link : CVE-2019-9943

Mitre link : CVE-2019-9943

Products Affected
No products.
CWE
CWE-276

Incorrect Default Permissions