In OMERO 5.3.3 or earlier a user could create an OriginalFile and adjust its path such that it now points to another user's file on the underlying filesystem, then manipulate the user's data.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2018-01-02T23:00:00

Updated: 2024-08-05T22:00:41.082Z

Reserved: 2018-01-02T00:00:00

Link: CVE-2017-1000438

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2018-01-02T23:29:00.460

Modified: 2019-10-03T00:03:26.223

Link: CVE-2017-1000438

cve-icon Redhat

No data.