Description

Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings. The REST login endpoint uses HTTP GET method with username and password passed as query parameters. Please check references regarding possible impact This issue affects Apache OpenMeetings: from 3.1.3 before 9.0.0. Users are recommended to upgrade to version 9.0.0, which fixes the issue.

INFO

Published Date :

2026-04-09T15:52:06.599Z

Last Modified :

2026-04-09T16:29:22.642Z

Source :

apache
AFFECTED PRODUCTS

The following products are affected by CVE-2026-34020 vulnerability.

Vendors Products
Apache
  • Openmeetings

CVSS Vulnerability Scoring System