|
|
Message-ID: <5fe9dbb2-d948-7040-fa65-cf9ebf8f9af2@apache.org> Date: Thu, 09 Apr 2026 14:18:19 +0000 From: Maxim Solodovnik <solomax@...che.org> To: oss-security@...ts.openwall.com Subject: CVE-2026-33005: Apache OpenMeetings: Insufficient checks in FileWebService Severity: moderate Affected versions: - Apache OpenMeetings 3.1.0 before 9.0.0 Description: Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings. Any registered user can query web service with their credentials and get files/sub-folders of any folder by ID (metadata only NOT contents). Metadata includes id, type, name and some other field. Full list of fields get be checked at FileItemDTO object. This issue affects Apache OpenMeetings: from 3.10 before 9.0.0. Users are recommended to upgrade to version 9.0.0, which fixes the issue. This issue is being tracked as OPENMEETINGS-2812 Credit: 4ra2n (A code security AI agent) (finder) References: https://openmeetings.apache.org/openmeetings-db/apidocs/org.apache.openmeetings.db/org/apache/openmeetings/db/dto/file/FileItemDTO.html https://openmeetings.apache.org/ https://www.cve.org/CVERecord?id=CVE-2026-33005 https://issues.apache.org/jira/browse/OPENMEETINGS-2812
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.