CVE-2023-29032: Apache OpenMeetings: allows bypass authentication
Published May 12, 2023
·Updated
An attacker that has gained access to certain private information can use this to act as other user.
Vendor: The Apache Software Foundation
Versions Affected: Apache OpenMeetings from 3.1.3 before 7.1.0
Affected Software
2 affected componentsFixes available
Apache OpenMeetings>=3.1.3<7.1.0
maven/org.apache.openmeetings:openmeetings-parent>=3.1.3<7.1.0
7.1.0
Event History
May 12, 2023
CVE Published
via MITRE·07:43 AM
Data Sourced
via MITRE·07:43 AM
DescriptionWeakness
Advisory Published
09:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2023-29032?
CVE-2023-29032 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2023-29032?
To address CVE-2023-29032, upgrade Apache OpenMeetings to version 7.1.0 or later.
3
What versions are affected by CVE-2023-29032?
CVE-2023-29032 affects Apache OpenMeetings versions from 3.1.3 up to, but not including, 7.1.0.
4
What is the impact of CVE-2023-29032?
An attacker who gains access to certain private information can impersonate other users due to CVE-2023-29032.
5
Which organization is responsible for CVE-2023-29032?
CVE-2023-29032 has been reported by The Apache Software Foundation.