CVE-2017-7673: Weak Encryption
Apache OpenMeetings 1.0.0 uses not very strong cryptographic storage, captcha is not used in registration and forget password dialogs and auth forms missing brute force protection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7673?
The severity of CVE-2017-7673 is classified as medium due to the lack of strong cryptographic storage and insufficient brute force protection.
How do I fix CVE-2017-7673?
To fix CVE-2017-7673, upgrade to a later version of Apache OpenMeetings that addresses these security weaknesses.
What software versions are affected by CVE-2017-7673?
CVE-2017-7673 affects Apache OpenMeetings versions 1.0.0 through 3.2.1.
What kind of vulnerabilities does CVE-2017-7673 include?
CVE-2017-7673 includes vulnerabilities related to inadequate cryptographic storage, missing captcha in forms, and lack of brute force protection.
Is CVE-2017-7673 being actively exploited?
As of now, there is no public indication that CVE-2017-7673 is being actively exploited, but it is recommended to address the vulnerability promptly.