Vulnerabilities (CVE)

Filtered by vendor Apache Subscribe
Filtered by product Openmeetings
Total 25 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-28936 1 Apache 1 Openmeetings 2024-11-21 N/A 5.3 MEDIUM
Attacker can access arbitrary recording/room Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.1.0
CVE-2023-28326 1 Apache 1 Openmeetings 2024-11-21 N/A 9.8 CRITICAL
Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.0.0 Description: Attacker can elevate their privileges in any room
CVE-2021-27576 1 Apache 1 Openmeetings 2024-11-21 5.0 MEDIUM 7.5 HIGH
If was found that the NetTest web service can be used to overload the bandwidth of a Apache OpenMeetings server. This issue was addressed in Apache OpenMeetings 6.0.0
CVE-2020-13951 1 Apache 1 Openmeetings 2024-11-21 5.0 MEDIUM 7.5 HIGH
Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack.
CVE-2018-1286 1 Apache 1 Openmeetings 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
In Apache OpenMeetings 3.0.0 - 4.0.1, CRUD operations on privileged users are not password protected allowing an authenticated attacker to deny service for privileged users.