PT-2021-17517 · Apache · Apache Openmeetings

Chi Tran

+2

·

Published

2021-03-15

·

Updated

2021-06-16

·

CVE-2021-27576

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache OpenMeetings versions prior to 6.0.0
Description The NetTest web service can be used to overload the bandwidth of an Apache OpenMeetings server. This issue was addressed in Apache OpenMeetings 6.0.0.
Recommendations For versions prior to 6.0.0, update to Apache OpenMeetings 6.0.0 to resolve the issue. As a temporary workaround, consider restricting access to the NetTest web service to minimize the risk of exploitation.

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-27576
GHSA-PX9F-597F-WMCF

Affected Products

Apache Openmeetings