Background
If an error occurred when resetting a user's password using the Forgot Password option in OMERO.web, the error message displayed on the Web page can disclose information about the user.
Impact
OMERO.web before 5.29.1
Patches
User should upgrade to 5.29.2 or higher
Workarounds
Disable the Forgot password option in OMERO.web using the omero.web.show_forgot_password configuration property1.
Thanks to Christopher Youd who reported the issue.
Open an issue in omero-web
Email us at security@openmicroscopy.org
Background
If an error occurred when resetting a user's password using the
Forgot Passwordoption in OMERO.web, the error message displayed on the Web page can disclose information about the user.Impact
OMERO.web before 5.29.1
Patches
User should upgrade to 5.29.2 or higher
Workarounds
Disable the
Forgot passwordoption in OMERO.web using theomero.web.show_forgot_passwordconfiguration property1.Thanks to Christopher Youd who reported the issue.
Open an issue in omero-web
Email us at security@openmicroscopy.org
Footnotes
https://omero.readthedocs.io/en/stable/sysadmins/config.html#omero.web.show_forgot_password ↩