CVE-2023-28326Missing Authentication for Critical Function in Software Foundation Apache Openmeetings

Severity
9.8CRITICALNVD
EPSS
1.1%
top 22.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 28

Description

Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.0.0 Description: Attacker can elevate their privileges in any room

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDapache/openmeetings2.07.0.0

🔴Vulnerability Details

3
GHSA
Apache OpenMeetings missing authentication and can allow user impersonation2023-03-28
OSV
Apache OpenMeetings missing authentication and can allow user impersonation2023-03-28
CVEList
Apache OpenMeetings: allows user impersonation2023-03-28
CVE-2023-28326 — CRITICAL severity | cvebase