affects OMERO.server versions 5.1.0 to 5.6.0
Permissions on OMERO model objects may be circumvented during certain operations such as move and delete.
The OMERO Blitz API offers several graph operations
that modify user data. The code checks permissions manually as it operates.
OMERO 5.6.1 improves the permissions query to take account of a model object's group context and ensure that all graph operations comply with the user's permissions.
This vulnerability is identified as CVE-2019-9943.
OMERO.server from 5.1.0 to 5.6.0 inclusive.
All OMERO.servers should be upgraded to at least 5.6.1.