CVE-2017-7673

CRITICAL

Apache OpenMeetings 1.0.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

Apache OpenMeetings 1.0.0 uses not very strong cryptographic storage, captcha is not used in registration and forget password dialogs and auth forms missing brute force protection.

References (2)

Core 2
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://markmail.org/message/3hshl26omwjo6c5i
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/99587

Scores

CVSS v3 9.8
EPSS 0.0040
EPSS Percentile 61.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-307 CWE-326
Status published
Products (23)
apache/openmeetings 1.0.0
apache/openmeetings 2.0
apache/openmeetings 2.1
apache/openmeetings 2.1.1
apache/openmeetings 2.2.0
apache/openmeetings 3.0.0
apache/openmeetings 3.0.1
apache/openmeetings 3.0.2
apache/openmeetings 3.0.3
apache/openmeetings 3.0.4
... and 13 more
Published Jul 17, 2017
Tracked Since Feb 18, 2026