2019-SV5 Bypass Filters

affects OMERO.server 5 versions 5.6.0 and earlier

back to Advisories

Synopsis

OMERO.server uses Hibernate Filters to protect sensitive data but it is possible to craft a query that can access some data indirectly.

Background

Some objects are hidden from normal users for security reasons. The OMERO.blitz API allows users to query the server for data. One may bypass the security filters by making those queries in an obscure manner.

OMERO 5.6.1 uses custom types to effect the hiding of sensitive fields. These take effect regardless of how the field was queried.

This vulnerability is identified as CVE-2019-16244.

Affected Packages

OMERO.server before 5.6.1.

Impact

Critical severity.

CVSS score 9.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C

Resolution

All OMERO.servers should be upgraded to at least 5.6.1.


back to top