oss-sec mailing list archives

CVE-2026-34020: Apache OpenMeetings: Login Credentials Passed via GET Query Parameters


From: Maxim Solodovnik <solomax () apache org>
Date: Thu, 09 Apr 2026 14:23:50 +0000

Severity: moderate 

Affected versions:

- Apache OpenMeetings 3.1.3 before 9.0.0

Description:

Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings.

The REST login endpoint uses HTTP GET method with username and password passed as query parameters. Please check 
references regarding possible impact


This issue affects Apache OpenMeetings: from 3.1.3 before 9.0.0.

Users are recommended to upgrade to version 9.0.0, which fixes the issue.

This issue is being tracked as OPENMEETINGS-2816 

Credit:

4ra2n (A code security AI agent) (finder)

References:

https://owasp.org/www-community/vulnerabilities/Information_exposure_through_query_strings_in_url
https://openmeetings.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-34020
https://issues.apache.org/jira/browse/OPENMEETINGS-2816


Current thread: