CVE-2017-7680: High severity Apache OpenMeetings vulnerability
Published Jul 14, 2017
·Updated
Apache OpenMeetings 1.0.0 has an overly permissive crossdomain.xml file. This allows for flash content to be loaded from untrusted domains.
Affected Software
21 affected components
Apache OpenMeetings=1.0.0
Apache OpenMeetings=2.0
Apache OpenMeetings=2.1
Apache OpenMeetings=2.1.1
Apache OpenMeetings=2.2.0
Apache OpenMeetings=3.0.0
Apache OpenMeetings=3.0.1
Apache OpenMeetings=3.0.2
Apache OpenMeetings=3.0.3
Apache OpenMeetings=3.0.4
Apache OpenMeetings=3.0.5
Apache OpenMeetings=3.0.6
Apache OpenMeetings=3.0.7
Apache OpenMeetings=3.1.0
Apache OpenMeetings=3.1.1
Apache OpenMeetings=3.1.2
Apache OpenMeetings=3.1.3
Apache OpenMeetings=3.1.4
Apache OpenMeetings=3.1.5
Apache OpenMeetings=3.2.0
Apache OpenMeetings=3.2.1
Event History
Jul 14, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-7680?
The severity of CVE-2017-7680 is considered high due to the potential for exploitation through untrusted domains.
2
How do I fix CVE-2017-7680?
To fix CVE-2017-7680, ensure that the crossdomain.xml file is properly configured to restrict access to only trusted domains.
3
What versions of Apache OpenMeetings are affected by CVE-2017-7680?
CVE-2017-7680 affects Apache OpenMeetings versions 1.0.0, 2.0, 2.1, 2.1.1, 2.2.0, and all 3.x versions up to 3.2.1.
4
What are the risks of not addressing CVE-2017-7680?
Not addressing CVE-2017-7680 increases the risk of exposing sensitive information through unauthorized access from untrusted sources.
5
Can CVE-2017-7680 lead to data breaches?
Yes, CVE-2017-7680 can potentially lead to data breaches by allowing malicious users to load harmful flash content.