High severity7.2NVD Advisory· Published May 12, 2023· Updated Jun 17, 2026
CVE-2023-29246
CVE-2023-29246
Description
An attacker who has gained access to an admin account can perform RCE via null-byte injection
Vendor: The Apache Software Foundation
Versions Affected: Apache OpenMeetings from 2.0.0 before 7.1.0
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.openmeetings:openmeetings-parentMaven | >= 2.0.0, < 7.1.0 | 7.1.0 |
Affected products
3cpe:2.3:a:apache:openmeetings:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:apache:openmeetings:*:*:*:*:*:*:*:*range: >=2.0.0,<7.1.0
- (no CPE)range: 2.0.0
Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-mg5h-f3q8-c96gghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-29246ghsaADVISORY
- github.com/apache/openmeetings/commit/8e65a1344157b2898f2922d49a0bd2105687c4a5ghsaWEB
- github.com/apache/openmeetings/commit/9f12a48994d0ad741ac140c52cbd2152f0d048d5ghsaWEB
- github.com/apache/openmeetings/commit/f91ff1917027625f066a9007694a31d06e69df3aghsaWEB
- issues.apache.org/jira/browse/OPENMEETINGS-2765ghsaWEB
- lists.apache.org/thread/230plvhbdx26m43b0sy942wlwt6kkmmrnvdMailing ListWEB
News mentions
0No linked articles in our index yet.