Lucene search

K
githubGitHub Advisory DatabaseGHSA-V93H-RWJ8-78QH
HistoryJul 06, 2023 - 9:14 p.m.

Apache OpenMeetings insufficient authorization vulnerability

2023-07-0621:14:56
CWE-697
GitHub Advisory Database
github.com
8
apache
openmeetings
authorization
vulnerability
attacker
recording
room

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

0.001 Low

EPSS

Percentile

40.8%

Attacker can access arbitrary recording/room

Vendor: The Apache Software Foundation

VersionsΒ Affected: Apache OpenMeetings from 2.0.0 before 7.1.0

Affected configurations

Vulners
Node
org.apache.openmeetings\openmeetingsMatchdb
OR
org.apache.openmeetings\openmeetingsMatchdb

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

0.001 Low

EPSS

Percentile

40.8%