Information Disclosure Vulnerability in OMERO.web by OME
CVE-2025-54791
5.3MEDIUM
What is CVE-2025-54791?
OMERO.web, a web-based client and plugin infrastructure by OME, is vulnerable to an information disclosure issue where error messages generated during the password reset process could inadvertently reveal sensitive user information. This exposure occurs when the 'Forgot Password' feature is utilized prior to version 5.29.2. To mitigate this risk, users are advised to upgrade to version 5.29.2 or disable the password reset option by modifying the configuration property 'omero.web.show_forgot_password'.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
omero-web < 5.29.2
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
