CVE-2017-7673

Apache OpenMeetings 1.0.0 uses not very strong cryptographic storage, captcha is not used in registration and forget password dialogs and auth forms missing brute force protection.
References
Link Resource
http://www.securityfocus.com/bid/99587 Third Party Advisory VDB Entry
http://markmail.org/message/3hshl26omwjo6c5i Mailing List Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:openmeetings:3.0.7:*:*:*:*:*:*:*
cpe:2.3:a:apache:openmeetings:3.1.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:openmeetings:3.1.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:openmeetings:2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:openmeetings:3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:openmeetings:3.0.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:openmeetings:3.0.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:openmeetings:2.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:openmeetings:2.1.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:openmeetings:3.0.3:*:*:*:*:*:*:*
cpe:2.3:a:apache:openmeetings:3.0.5:*:*:*:*:*:*:*
cpe:2.3:a:apache:openmeetings:2.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:openmeetings:3.1.4:*:*:*:*:*:*:*
cpe:2.3:a:apache:openmeetings:3.2.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:openmeetings:3.1.3:*:*:*:*:*:*:*
cpe:2.3:a:apache:openmeetings:3.0.6:*:*:*:*:*:*:*
cpe:2.3:a:apache:openmeetings:3.1.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:openmeetings:3.0.4:*:*:*:*:*:*:*
cpe:2.3:a:apache:openmeetings:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:openmeetings:3.1.5:*:*:*:*:*:*:*
cpe:2.3:a:apache:openmeetings:3.2.1:*:*:*:*:*:*:*

Information

Published : 2017-07-17 06:18

Updated : 2019-10-02 17:03


NVD link : CVE-2017-7673

Mitre link : CVE-2017-7673


JSON object : View

CWE
CWE-326

Inadequate Encryption Strength

CWE-307

Improper Restriction of Excessive Authentication Attempts

Advertisement

dedicated server usa

Products Affected

apache

  • openmeetings