oss-sec mailing list archives

CVE-2017-7664 - Apache OpenMeetings - Missing XML Validation


From: Maxim Solodovnik <solomax666 () gmail com>
Date: Thu, 13 Jul 2017 23:22:36 +0700

Severity: High

Vendor: The Apache Software Foundation

Versions Affected: Apache OpenMeetings 3.1.0

Description: Uploaded XML documents were not correctly validated
CVE-2017-7664

The issue was fixed in 3.3.0
All users are recommended to upgrade to Apache OpenMeetings 3.3.0

Credit: This issue was identified by Security Innovation


-- 
WBR
Maxim aka solomax


Current thread: