Moderate severityNVD Advisory· Published May 12, 2023· Updated Oct 10, 2024
Apache OpenMeetings: insufficient check of invitation hash
CVE-2023-28936
Description
Attacker can access arbitrary recording/room
Vendor: The Apache Software Foundation
Versions Affected: Apache OpenMeetings from 2.0.0 before 7.1.0
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.openmeetings:openmeetings-dbMaven | >= 2.0.0, < 7.1.0 | 7.1.0 |
Affected products
2- Range: 2.0.0
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-v93h-rwj8-78qhghsaADVISORY
- lists.apache.org/thread/y6vng44c22ll221rtvsv208x1pbjmdocghsavendor-advisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2023-28936ghsaADVISORY
- github.com/apache/openmeetings/commit/a28dea888fca1c5c3e0ce4c8a4c62f501aebe0cdghsaWEB
- issues.apache.org/jira/browse/OPENMEETINGS-2762ghsaWEB
News mentions
0No linked articles in our index yet.