CVE-2023-29246, GHSA-mg5h-f3q8-c96g
maven/org.apache.openmeetings/openmeetings-parent
Improper Input Validation
An attacker who has gained access to an admin account can perform RCE via null-byte injection
Vendor: The Apache Software Foundation
Versions Affected: Apache OpenMeetings from 2.0.0 before 7.1.0
All versions starting from 2.0.0 before 7.1.0
Upgrade to version 7.1.0 or above.
2023-05-15
source |