Lucene search

K
githubGitHub Advisory DatabaseGHSA-3R48-3M8R-4R9W
HistoryMar 28, 2023 - 3:30 p.m.

Apache OpenMeetings missing authentication and can allow user impersonation

2023-03-2815:30:18
CWE-306
GitHub Advisory Database
github.com
7
apache
openmeetings
authentication
vulnerability
user impersonation
privilege escalation

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.054 Low

EPSS

Percentile

93.2%

The Apache Software Foundation’s OpenMeetings from 2.0.0 before 7.0.0 is missing authentication on meeting invitation URLs. An invitation URL contains a hash that automatically logs in as the invited user. An unauthorized user could obtain this URL and log in to the meeting as an invited user, in effect elevating their privileges in the meeting room. OpenMeetings 7.0.0 disables this option if a contact is not selected.

Affected configurations

Vulners
Node
org.apache.openmeetings\openmeetingsMatchparent
OR
org.apache.openmeetings\openmeetingsMatchparent

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.054 Low

EPSS

Percentile

93.2%

Related for GHSA-3R48-3M8R-4R9W