CVE-2023-29032

Severity
8.1HIGH
EPSS
0.2%
top 58.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 12

Description

An attacker that has gained access to certain private information can use this to act as other user. Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 3.1.3 before 7.1.0

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages3 packages

🔴Vulnerability Details

3
CVEList
Apache OpenMeetings: allows bypass authentication2023-05-12
GHSA
Apache OpenMeetings Improper Authentication vulnerability2023-05-12
OSV
Apache OpenMeetings Improper Authentication vulnerability2023-05-12
CVE-2023-29032 (HIGH CVSS 8.1) | An attacker that has gained access | cvebase.io