Show filters
25 Total Results
Displaying 1-10 of 25
Sort by:
Attacker Value
Unknown

CVE-2024-54676

Disclosure Date: January 08, 2025 (last updated January 16, 2025)
Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Default clustering instructions at https://openmeetings.apache.org/Clustering.html  doesn't specify white/black lists for OpenJPA this leads to possible deserialisation of untrusted data. Users are recommended to upgrade to version 8.0.0 and update their startup scripts to include the relevant 'openjpa.serialization.class.blacklist' and 'openjpa.serialization.class.whitelist' configurations as shown in the documentation.
Attacker Value
Unknown

CVE-2023-29246

Disclosure Date: May 12, 2023 (last updated October 08, 2023)
An attacker who has gained access to an admin account can perform RCE via null-byte injection Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.1.0
Attacker Value
Unknown

CVE-2023-29032

Disclosure Date: May 12, 2023 (last updated October 08, 2023)
An attacker that has gained access to certain private information can use this to act as other user. Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 3.1.3 before 7.1.0
Attacker Value
Unknown

CVE-2023-28936

Disclosure Date: May 12, 2023 (last updated October 08, 2023)
Attacker can access arbitrary recording/room Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.1.0
Attacker Value
Unknown

CVE-2023-28326

Disclosure Date: March 28, 2023 (last updated November 08, 2023)
Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.0.0 Description: Attacker can elevate their privileges in any room
Attacker Value
Unknown

CVE-2021-27576

Disclosure Date: March 15, 2021 (last updated November 28, 2024)
If was found that the NetTest web service can be used to overload the bandwidth of a Apache OpenMeetings server. This issue was addressed in Apache OpenMeetings 6.0.0
Attacker Value
Unknown

CVE-2020-13951

Disclosure Date: September 30, 2020 (last updated November 08, 2023)
Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack.
Attacker Value
Unknown

CVE-2018-1286

Disclosure Date: February 28, 2018 (last updated November 08, 2023)
In Apache OpenMeetings 3.0.0 - 4.0.1, CRUD operations on privileged users are not password protected allowing an authenticated attacker to deny service for privileged users.
0
Attacker Value
Unknown

CVE-2016-8736

Disclosure Date: October 12, 2017 (last updated November 26, 2024)
Apache OpenMeetings before 3.1.2 is vulnerable to Remote Code Execution via RMI deserialization attack.
0
Attacker Value
Unknown

CVE-2017-7680

Disclosure Date: July 17, 2017 (last updated November 26, 2024)
Apache OpenMeetings 1.0.0 has an overly permissive crossdomain.xml file. This allows for flash content to be loaded from untrusted domains.
0