VDB
Sign up
LOW

GHSA-j4gv-6x9v-v23g

OMERO.web uses jquery-form library, which may be vulnerable to XSS attack

Quick fix

GHSA-j4gv-6x9v-v23g — omero-web: upgrade to the fixed version with the command below.

pip install --upgrade 'omero-web>=5.29.3'

Details

### Impact OMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks.

### Patches User should upgrade OMERO.web to 5.29.3 or higher.

### Workarounds None.

### Resources https://github.com/jquery-form/form/issues/604

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/omero-web
Introduced in: 0Fixed in: 5.29.3
Fixpip install --upgrade 'omero-web>=5.29.3'

References