CVE-2017-7673
Apache OpenMeetings has Inadequate Encryption Strength
9.8
CRITICAL
CVSS 3.1
EPSS 1.6%
Description
Apache OpenMeetings 1.0.0 uses not very strong cryptographic storage, captcha is not used in registration and forget password dialogs and auth forms missing brute force protection.
How to fix CVE-2017-7673
To remediate CVE-2017-7673, upgrade the affected package to a fixed version below.
- Maven/org.apache.openmeetings:openmeetings-parent—upgrade to 3.3.0 or later
Is CVE-2017-7673 being exploited?
Low — EPSS is 1.6%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 1.0.0, < 3.3.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |