GHSA-vwxv-frj6-fhc9 · Severity: medium · Ecosystem: pip — OMERO-web Sensitive Data Exposure
OMERO.web before 5.6.3 optionally allows sensitive data elements (e.g., a session key) to be passed as URL query parameters. If an attacker tricks a user into clicking a malicious link in OMERO.web, the information in the query parameters may be exposed in the Referer header seen by the target. Information in the URL path such as object IDs may also be exposed.
Conclusion & alert: CVE-2020-7932 is rated Moderate Risk (41.4/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.34%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-03-30 | 0.67% | 0.34% | -0.33% |
| 2 | 2025-03-29 | 0.34% | 0.67% | +0.33% |
| 3 | 2025-03-17 | — | 0.34% | — |
Full EPSS history (8 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.7 | 3.1 | MEDIUM |
|
2.1 | 3.6 | [email protected] |
| 3.5 | 2.0 | LOW |
|
6.8 | 2.9 | [email protected] |
GHSA-vwxv-frj6-fhc9 · Severity: medium · Ecosystem: pip — OMERO-web Sensitive Data Exposure
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| openmicroscopy | omero.web | < 5.6.3 | cpe:2.3:a:openmicroscopy:omero.web:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://www.openmicroscopy.org/security/advisories/2019-SV4/ | Vendor Advisory |