Description
An attacker who has gained access to an admin account can perform RCE via null-byte injection Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.1.0
Remediation
References
https://lists.apache.org/thread/230plvhbdx26m43b0sy942wlwt6kkmmr
Related Vulnerabilities
CVE-2016-4055 Vulnerability in maven package org.webjars.bowergithub.moment:moment
CVE-2020-11973 Vulnerability in maven package org.apache.camel:camel-netty
CVE-2023-41835 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2020-2256 Vulnerability in maven package org.jenkins-ci.plugins:pipeline-maven-parent