CVE-2025-54791 ("OMERO.web displays unnecessary user information when requesting to reset the password")

Affects OMERO.web <=5.29.1

back to Advisories

Synopsis

OMERO.web displays unnecessary user information when requesting to reset the password

Background

If an error occurred when resetting a user's password using the Forgot Password option in OMERO.web, the error message displayed on the Web page can disclose information about the user.

Affected Packages

OMERO.web <=5.29.1

Impact

Moderate severity.

Workaround

Disable the Forgot password option in OMERO.web using the omero.web.show_forgot_password configuration property.

Resolution

All OMERO.web deployments should be upgraded to at least 5.29.2.


back to top