2017-SV2 Edit in RW Group

affects OMERO versions 5.2.7 and earlier

back to Advisories

Synopsis

A normal user in a read-write group can edit official scripts.

Background

Official scripts are in the "user" group. A normal user in a read-write group can edit official scripts because the server would check the current group permissions and see they were permissive. The fix was to increase the cases in which the server would instead look at the group permissions of the object actually being edited rather than those of the user's current group.

Affected Packages

OMERO.server up to and including 5.2.7.

Impact

High severity. Any users in a read-write group could edit any script and corrupt or delete data in OMERO.server.

Workaround

None

Resolution

All OMERO.servers should be upgraded to at least 5.2.8.


back to top