Description
An attacker that has gained access to certain private information can use this to act as other user. Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 3.1.3 before 7.1.0
Remediation
References
https://lists.apache.org/thread/j2d6mg3rzcphfd8vvvk09d8p4o9lvnqp
Related Vulnerabilities
CVE-2020-26217 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2017-7681 Vulnerability in maven package org.apache.openmeetings:openmeetings-server
CVE-2020-6426 Vulnerability in npm package electron
CVE-2017-12882 Vulnerability in maven package org.springframework.batch:spring-batch-admin
CVE-2023-50164 Vulnerability in maven package org.apache.struts:struts2-core