CVE-2024-35180
MEDIUMDescription
OMERO.web provides a web based client and plugin infrastructure. There is currently no escaping or validation of the `callback` parameter that can be passed to various OMERO.web endpoints that have JSONP enabled. This vulnerability has been patched in version 5.26.0.
Is your site exposed to CVE-2024-35180?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| openmicroscopy | omero-web |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-35180? +
How severe is CVE-2024-35180? +
What products are affected by CVE-2024-35180? +
How do I check if I'm vulnerable to CVE-2024-35180? +
Related Vulnerabilities
Minder is an open source software supply chain security platform. In Minder Helm version 0.20241106.3386+ref.2507dbf and Minder Go versions from …
An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in …
os/linux/elf.rb in Homebrew brew before 4.2.20 uses ldd to load ELF files obtained from untrusted sources, which allows attackers to …
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Versions 0.6.224 and prior contain a code …
In WinZip through 29.0, there is a Mark-of-the-Web Bypass Vulnerability because of an incomplete fix for CVE-2024-8811. This vulnerability allows …
An issue was discovered in Ankitects Anki through 25.02. A crafted shared deck can result in attacker-controlled access to the …