CVE-2023-28326
Apache OpenMeetings missing authentication and can allow user impersonation
9.8
CRITICAL
CVSS 3.1
EPSS 1.3%
Description
The Apache Software Foundation's OpenMeetings from 2.0.0 before 7.0.0 is missing authentication on meeting invitation URLs. An invitation URL contains a hash that automatically logs in as the invited user. An unauthorized user could obtain this URL and log in to the meeting as an invited user, in effect elevating their privileges in the meeting room. OpenMeetings 7.0.0 disables this option if a contact is not selected.
How to fix CVE-2023-28326
To remediate CVE-2023-28326, upgrade the affected package to a fixed version below.
- —upgrade to 7.0.0 or later
Is CVE-2023-28326 being exploited?
Low — EPSS is 1.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 2.0.0, < 7.0.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |