Show filters
25 Total Results
Displaying 1-10 of 25
Sort by:
Attacker Value
Unknown
CVE-2024-54676
Disclosure Date: January 08, 2025 (last updated January 16, 2025)
Vendor: The Apache Software Foundation
Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0
Description: Default clustering instructions at https://openmeetings.apache.org/Clustering.html doesn't specify white/black lists for OpenJPA this leads to possible deserialisation of untrusted data.
Users are recommended to upgrade to version 8.0.0 and update their startup scripts to include the relevant 'openjpa.serialization.class.blacklist' and 'openjpa.serialization.class.whitelist' configurations as shown in the documentation.
0
Attacker Value
Unknown
CVE-2023-29246
Disclosure Date: May 12, 2023 (last updated October 08, 2023)
An attacker who has gained access to an admin account can perform RCE via null-byte injection
Vendor: The Apache Software Foundation
Versions Affected: Apache OpenMeetings from 2.0.0 before 7.1.0
0
Attacker Value
Unknown
CVE-2023-29032
Disclosure Date: May 12, 2023 (last updated October 08, 2023)
An attacker that has gained access to certain private information can use this to act as other user.
Vendor: The Apache Software Foundation
Versions Affected: Apache OpenMeetings from 3.1.3 before 7.1.0
0
Attacker Value
Unknown
CVE-2023-28936
Disclosure Date: May 12, 2023 (last updated October 08, 2023)
Attacker can access arbitrary recording/room
Vendor: The Apache Software Foundation
Versions Affected: Apache OpenMeetings from 2.0.0 before 7.1.0
0
Attacker Value
Unknown
CVE-2023-28326
Disclosure Date: March 28, 2023 (last updated November 08, 2023)
Vendor: The Apache Software Foundation
Versions Affected: Apache OpenMeetings from 2.0.0 before 7.0.0
Description: Attacker can elevate their privileges in any room
0
Attacker Value
Unknown
CVE-2021-27576
Disclosure Date: March 15, 2021 (last updated November 28, 2024)
If was found that the NetTest web service can be used to overload the bandwidth of a Apache OpenMeetings server. This issue was addressed in Apache OpenMeetings 6.0.0
0
Attacker Value
Unknown
CVE-2020-13951
Disclosure Date: September 30, 2020 (last updated November 08, 2023)
Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack.
0
Attacker Value
Unknown
CVE-2018-1286
Disclosure Date: February 28, 2018 (last updated November 08, 2023)
In Apache OpenMeetings 3.0.0 - 4.0.1, CRUD operations on privileged users are not password protected allowing an authenticated attacker to deny service for privileged users.
0
Attacker Value
Unknown
CVE-2016-8736
Disclosure Date: October 12, 2017 (last updated November 26, 2024)
Apache OpenMeetings before 3.1.2 is vulnerable to Remote Code Execution via RMI deserialization attack.
0
Attacker Value
Unknown
CVE-2017-7680
Disclosure Date: July 17, 2017 (last updated November 26, 2024)
Apache OpenMeetings 1.0.0 has an overly permissive crossdomain.xml file. This allows for flash content to be loaded from untrusted domains.
0