In Apache OpenMeetings 3.0.0 - 4.0.1, CRUD operations on privileged users are not password protected allowing an authenticated attacker to deny service for privileged users.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.apache.openmeetings:openmeetings-parent(Maven) | 3.0.0 | 4.0.2 | N/A |
CVSS Metrics