Information Disclosure Vulnerability in OMERO.web by OME
CVE-2025-54791

5.3MEDIUM

Key Information:

Vendor

Ome

Status
Vendor
CVE Published:
13 August 2025

What is CVE-2025-54791?

OMERO.web, a web-based client and plugin infrastructure by OME, is vulnerable to an information disclosure issue where error messages generated during the password reset process could inadvertently reveal sensitive user information. This exposure occurs when the 'Forgot Password' feature is utilized prior to version 5.29.2. To mitigate this risk, users are advised to upgrade to version 5.29.2 or disable the password reset option by modifying the configuration property 'omero.web.show_forgot_password'.

Affected Version(s)

omero-web < 5.29.2

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-54791 : Information Disclosure Vulnerability in OMERO.web by OME