A vulnerability (CVE-2023-28936) has been fixed in the Apache OpenMeetings web conference server, which allows access to arbitrary recordings and chat rooms. The issue has been assigned a critical severity level. This vulnerability was caused by improper hash verification used for connecting new participants. The flaw affects versions starting from 2.0.0 and has been resolved in the recently released Apache OpenMeetings 7.1.0 update.
Additionally, two less severe vulnerabilities have been addressed in Apache OpenMeetings 7.1.0:
- CVE-2023-29032 — the ability to bypass authentication. An attacker who knows certain confidential information about a user can impersonate another user.
- CVE-2023-29246 — the possibility of injecting a null character, which can be exploited to execute custom code on server if access to the OpenMeetings administrator account is available.
Source: opennet.ru
