CVE-2021-27576: Uncontrolled Resource Consumption in Apache OpenMeetings server
If was found that the NetTest web service can be used to overload the bandwidth of a Apache OpenMeetings server. This issue was addressed in Apache OpenMeetings 6.0.0
References
- github.com/advisories/GHSA-px9f-597f-wmcf
- github.com/apache/openmeetings/commit/060a3114ad759931aeb42cd9afa9d1ebb39d3075
- github.com/apache/openmeetings/commit/afe26c950b127776f2dfe920abff41a584874de8
- github.com/apache/openmeetings/commit/cbdfd2f9731a8fe3daa9b4adf5da4a063fde161d
- issues.apache.org/jira/browse/OPENMEETINGS-2551
- lists.apache.org/thread.html/r9bb615bd70a0197368f5f3ffc887162686caeb0b5fc30592a7a871e9%40%3Cuser.openmeetings.apache.org%3E
- nvd.nist.gov/vuln/detail/CVE-2021-27576
- openmeetings.apache.org/security.html
Detect and mitigate CVE-2021-27576 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →