OMERO.web provides a web based client and plugin infrastructure. Prior to version 5.29.2, if an error occurred when resetting a user's password using the Forgot Password option in OMERO.web, the error message displayed on the Web page can disclose information about the user. This issue has been patched in version 5.29.2. A workaround involves disabling the Forgot password option in OMERO.web using the omero.web.show_forgot_password configuration property.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-24567 OMERO.web displays unecessary user information when requesting password reset
Github GHSA Github GHSA GHSA-gpmg-4x4g-mr5r OMERO.web displays unecessary user information when requesting password reset
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 23 Sep 2025 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Openmicroscopy
Openmicroscopy omero-web
CPEs cpe:2.3:a:openmicroscopy:omero-web:*:*:*:*:*:*:*:*
Vendors & Products Openmicroscopy
Openmicroscopy omero-web

Wed, 13 Aug 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 13 Aug 2025 14:15:00 +0000

Type Values Removed Values Added
Description OMERO.web provides a web based client and plugin infrastructure. Prior to version 5.29.2, if an error occurred when resetting a user's password using the Forgot Password option in OMERO.web, the error message displayed on the Web page can disclose information about the user. This issue has been patched in version 5.29.2. A workaround involves disabling the Forgot password option in OMERO.web using the omero.web.show_forgot_password configuration property.
Title OMERO.web displays unecessary user information when requesting to reset the password
Weaknesses CWE-209
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-08-13T14:25:28.402Z

Reserved: 2025-07-29T16:50:28.394Z

Link: CVE-2025-54791

cve-icon Vulnrichment

Updated: 2025-08-13T14:25:24.284Z

cve-icon NVD

Status : Analyzed

Published: 2025-08-13T14:15:32.580

Modified: 2025-09-23T18:13:48.487

Link: CVE-2025-54791

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.