CVE detail
CVE-2021-21377 — CVE-2021-21377
Published 2021-03-23 · Modified 2026-06-17 · Vendor openmicroscopy · Product omero.web · Source nvd
MEDIUM
severity
CVSS-derived band
0.0083
EPSS probability
exploitation probability, 30d
54.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 supports redirection to a given URL after performing login or switching the group context. These URLs are not validated, allowing redirection to untrusted sites. OMERO.web 5.9.0 adds URL validation before redirecting. External URLs are not considered valid, unless specified in the omero.web.redirect_allowed_hosts setting.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References