Information Disclosure Vulnerability in OMERO.web by OME
CVE-2025-54791
5.3MEDIUM
What is CVE-2025-54791?
OMERO.web, a web-based client and plugin infrastructure by OME, is vulnerable to an information disclosure issue where error messages generated during the password reset process could inadvertently reveal sensitive user information. This exposure occurs when the 'Forgot Password' feature is utilized prior to version 5.29.2. To mitigate this risk, users are advised to upgrade to version 5.29.2 or disable the password reset option by modifying the configuration property 'omero.web.show_forgot_password'.
Affected Version(s)
omero-web < 5.29.2