OMERO.web displays unecessary user information when requesting password reset
Description
Published by the National Vulnerability Database
Aug 13, 2025
Published to the GitHub Advisory Database
Aug 13, 2025
Reviewed
Aug 13, 2025
Last updated
Aug 27, 2025
Background
If an error occurred when resetting a user's password using the
Forgot Password
option in OMERO.web, the error message displayed on the Web page can disclose information about the user.Impact
OMERO.web before 5.29.1
Patches
User should upgrade to 5.29.2 or higher
Workarounds
Disable the
Forgot password
option in OMERO.web using theomero.web.show_forgot_password
configuration property1.Thanks to Christopher Youd who reported the issue.
Open an issue in omero-web
Email us at [email protected]
References
Footnotes
https://omero.readthedocs.io/en/stable/sysadmins/config.html#omero.web.show_forgot_password ↩