CVE-2026-33005
- EPSS 0.14%
- Veröffentlicht 09.04.2026 15:52:50
- Zuletzt bearbeitet 15.04.2026 15:27:05
Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings. Any registered user can query web service with their credentials and get files/sub-folders of any folder by ID (metadata only NOT contents). Metadata includes id, typ...
CVE-2026-33266
- EPSS 0.07%
- Veröffentlicht 09.04.2026 15:52:36
- Zuletzt bearbeitet 15.04.2026 15:21:55
Use of Hard-coded Cryptographic Key vulnerability in Apache OpenMeetings. The remember-me cookie encryption key is set to default value in openmeetings.properties and not being auto-rotated. In case OM admin hasn't changed the default encryption key...
CVE-2026-34020
- EPSS 0.09%
- Veröffentlicht 09.04.2026 15:52:06
- Zuletzt bearbeitet 15.04.2026 15:21:20
Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings. The REST login endpoint uses HTTP GET method with username and password passed as query parameters. Please check references regarding possible impact This...
CVE-2024-54676
- EPSS 6.12%
- Veröffentlicht 08.01.2025 09:15:07
- Zuletzt bearbeitet 15.01.2025 15:50:39
Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Default clustering instructions at https://openmeetings.apache.org/Clustering.html doesn't specify white/black lists for OpenJPA th...
CVE-2023-29246
- EPSS 0.11%
- Veröffentlicht 12.05.2023 08:15:08
- Zuletzt bearbeitet 21.11.2024 07:56:45
An attacker who has gained access to an admin account can perform RCE via null-byte injection Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.1.0
CVE-2023-29032
- EPSS 0.19%
- Veröffentlicht 12.05.2023 08:15:08
- Zuletzt bearbeitet 21.11.2024 07:56:25
An attacker that has gained access to certain private information can use this to act as other user. Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 3.1.3 before 7.1.0
CVE-2023-28936
- EPSS 0.45%
- Veröffentlicht 12.05.2023 08:15:08
- Zuletzt bearbeitet 21.11.2024 07:56:15
Attacker can access arbitrary recording/room Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.1.0
CVE-2023-28326
- EPSS 1.05%
- Veröffentlicht 28.03.2023 13:15:07
- Zuletzt bearbeitet 21.11.2024 07:54:50
Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.0.0 Description: Attacker can elevate their privileges in any room
CVE-2021-27576
- EPSS 4.5%
- Veröffentlicht 15.03.2021 09:15:12
- Zuletzt bearbeitet 21.11.2024 05:58:13
If was found that the NetTest web service can be used to overload the bandwidth of a Apache OpenMeetings server. This issue was addressed in Apache OpenMeetings 6.0.0
CVE-2020-13951
- EPSS 73.29%
- Veröffentlicht 30.09.2020 18:15:21
- Zuletzt bearbeitet 21.11.2024 05:02:13
Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack.