CVE-2023-29246: Apache OpenMeetings: allows null-byte Injection
Published May 12, 2023
·Updated
An attacker who has gained access to an admin account can perform RCE via null-byte injection
Vendor: The Apache Software Foundation
Versions Affected: Apache OpenMeetings from 2.0.0 before 7.1.0
Affected Software
2 affected componentsFixes available
Apache OpenMeetings>=2.0.0<7.1.0
maven/org.apache.openmeetings:openmeetings-parent>=2.0.0<7.1.0
7.1.0
Event History
May 12, 2023
CVE Published
via MITRE·07:43 AM
Data Sourced
via MITRE·07:43 AM
DescriptionWeakness
Advisory Published
09:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2023-29246?
CVE-2023-29246 has a high severity rating due to the potential for remote code execution (RCE) via null-byte injection.
2
How do I fix CVE-2023-29246?
To fix CVE-2023-29246, upgrade Apache OpenMeetings to version 7.1.0 or later.
3
Who is affected by CVE-2023-29246?
CVE-2023-29246 affects all versions of Apache OpenMeetings from 2.0.0 before 7.1.0.
4
What type of vulnerability is CVE-2023-29246?
CVE-2023-29246 is a remote code execution (RCE) vulnerability.
5
What can an attacker do with CVE-2023-29246?
An attacker with access to an admin account can exploit CVE-2023-29246 to execute arbitrary code on the server.