CVE-2021-27576: Apache OpenMeetings: bandwidth can be overloaded with public web service
Published Mar 15, 2021
·Updated
If was found that the NetTest web service can be used to overload the bandwidth of a Apache OpenMeetings server. This issue was addressed in Apache OpenMeetings 6.0.0
Affected Software
1 affected component
Apache OpenMeetings>=4.0.0<6.0.0
Event History
Mar 15, 2021
CVE Published
via MITRE·09:05 AM
Data Sourced
via MITRE·09:05 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-27576?
CVE-2021-27576 has a medium severity rating due to its potential for bandwidth overload.
2
How do I fix CVE-2021-27576?
To fix CVE-2021-27576, update your Apache OpenMeetings server to version 6.0.0 or later.
3
What are the consequences of CVE-2021-27576?
Exploitation of CVE-2021-27576 can lead to denial of service by overloading the server's bandwidth.
4
Which versions of Apache OpenMeetings are affected by CVE-2021-27576?
CVE-2021-27576 affects Apache OpenMeetings versions from 4.0.0 up to, but not including, 6.0.0.
5
Is there a patch for CVE-2021-27576?
Yes, the patch for CVE-2021-27576 is included in the upgrade to Apache OpenMeetings 6.0.0.