#OpenMeeting
We at @freepress.bsky.social are outside & inside the FCC today, as the monthly public meeting takes place.

The agenda is mostly technical issues. But we’re here to keep watch on Brendan Carr and demand accountability for his blatant censorship.

#OpenMeeting #FirstAmendment #ImpeachCarr
April 30, 2026 at 3:09 PM
#Advisoryboards bring professional and lived experience to the decision-making table, host public engagement, and get into the nitty gritty of #Asheville’s budgets, plans, and policies.

#civics #civics101 #disasterrecovery #civicengagement #publicengagement #openmeeting #MondayMinute
July 21, 2025 at 1:44 PM
💥Announcement! Tuesday 22.09.2026💥

🔥✊🏾Student Collective Open Meeting✊🏾🔥

Tuesday, 22.09.2026 | 6.00 pm | TU Ma Building, Straße des 17. Juni 136, 10623 Berlin

Directions: U2, bus 245, M45 to Ernst-Reuter-Platz

📣 Call to action: demo-ticker-berlin.org?p=8750

#b2209 #OpenMeeting
September 21, 2026 at 9:58 AM
💥Ankündigung! Mittwoch 01.07.2026💥

⚧️✊🏾Sozialistischer Feminismus und Klassenkampf✊🏾⚧️

Mittwoch, 01.07.2026 | 18:30 Uhr | Manifest Bücher & Café, Graefestraße 14, 10967 Berlin

Anreise: M41 Graefestraße | U8 Schönleinstraße

📣 Aufruf: asanb.noblogs.org?p=18349

#b0107 #OpenMeeting
June 30, 2026 at 7:49 PM
Directions: Buses 50, 106, 221; Tram M13 to Seestraße/Amrumer Straße | U9 to Amrumer Straße

#b2008 #OpenMeeting
2/2
August 19, 2026 at 11:26 AM
New post. I filed an Open Meeting Law complaint against the Chicopee City Council because it doesn't OCR its agendas or minutes. skynet-times.blogspot.com/2024/12/meta...

#massachusetts #pinkslime #localnews #westernmass #chicopee #mapoli #openmeeting #OCR #ADA
[meta] I filed an Open Meeting Law complaint against the Chicopee City Council
On December 12 I filed an open meeting law complaint against the Chicopee City Council because it does not OCR any of its published meetin...
skynet-times.blogspot.com
December 13, 2024 at 9:22 PM
Oklahoma's Supreme Court narrowly struck down controversial changes to #SocialStudies standards and ordered use of the 2019 standards until new ones are approved by the State Board of #oklaed.

Justices said a Feb. 27 vote violated the #OpenMeeting Act.

nondoc.com/2025/12/16/o...
OK Supreme Court strikes 2025 social studies standards for violating Open Meeting Act
The Oklahoma Supreme Court stuck down the revised 2025 social studies standards, finding their approval violated the Open Meetings Act.
nondoc.com
December 17, 2025 at 3:14 PM
Directions: Buses 50, 106, 221; Tram M13 to Seestraße/Amrumer Straße | U9 to Amrumer Straße

#b1709 #OpenMeeting
2/2
September 16, 2026 at 4:47 AM
💥Announcement! Thursday 17.09.2026💥

🏳️‍⚧️✊🏾Meet-up for LGBTQIA+ and female refugees✊🏾🏳️‍🌈

Thursday, 17.09.2026 | 4.30 pm | Citti Punkt e.V., Brüsseler Straße 36 A, 13353 Berlin

📣 Call to action: t.me/BerlinDemosE...

#b1709 #OpenMeeting
1/2
September 16, 2026 at 4:46 AM
💥Announcement! Thursday 03.09.2026💥

🏳️‍⚧️✊🏾Meet-up for LGBTQIA+ and female refugees✊🏾🏳️‍🌈

03.09.2026 | 4.30 pm | Cittipunkt e.V., Brüsseler Straße 36 A, 13353 Berlin

Arrival: Buses 50, 106, 221; Tram M13 to Seestraße/Amrumer Straße | U9 to Amrumer Straße

📣 Call: t.me/BerlinDemosE...

#b0309 #OpenMeeting
Berlin Demos English
*automatic translation* 💥Announcement! Thursday 03.09.2026💥 🏳️‍⚧️✊🏾Meet-up for LGBTQIA+ and female refugees✊🏾🏳️‍🌈 Thursday, 03.09.2026 | 4.30 pm | Cittipunkt e.V., Brüsseler Straße 36 A, 13353 Berl...
t.me
September 2, 2026 at 12:50 PM
💥Announcement Thursday 20.08.2026💥

🏳️‍⚧️✊🏾Meet-up for LGBTQIA+ and female refugees✊🏾🏳️‍🌈

Thursday, 20.08.2026 | 4.30 pm | Citti Punkt e.V., Brüsseler Straße 36 A, 13353 Berlin

📣 Call to action: asanb.noblogs.org?p=19120 - @women_queer_exchange

#b2008 #OpenMeeting
1/2
August 19, 2026 at 11:26 AM
Directions: Buses 50, 106, 221; Tram M13 to Seestraße/Amrumer Straße | U9 to Amrumer Straße

#b0608 #OpenMeeting
2/2
August 5, 2026 at 1:26 PM
💥Announcement Thursday 06.08.2026💥

🏳️‍⚧️✊🏾Meet-up for LGBTQIA+ and female refugees✊🏾🏳️‍🌈

Thursday, 06.08.2026 | 4.30 pm | Citti Punkt e.V., Brüsseler Straße 36 A, 13353 Berlin

📣Call to action: asanb.noblogs.org?p=18962 - @women_queer_exchange

#b0608 #OpenMeeting
1/2
August 5, 2026 at 1:26 PM
Directions: Buses 50, 106, 221; Tram M13 to Seestraße/Amrumer Straße | U9 to Amrumer Straße

#b1607 #OpenMeeting
2/2
July 15, 2026 at 3:15 PM
💥Announcement Thursday 16.07.2026💥

🏳️‍⚧️✊🏾LGBTQIA+ and Female Refugees’ Meeting✊🏾🏳️‍🌈

Thursday, 16.07.2026 | 4.30 pm | Cittipunkt e.V., Brüsseler Straße 36 A, 13353 Berlin

📣 Call to action: asanb.noblogs.org?p=18583 - @women_queer_exchange

#b1607 #OpenMeeting
1/2
July 15, 2026 at 3:14 PM
Directions: Buses 50, 106, 221; Tram M13 to Seestraße/Amrumer Straße | U9 to Amrumer Straße

🏳️‍⚧️🏳️‍🌈on Thursday 2 of Juli, we invite you again to our hangout for LGBTQIA and Women Refugees and Non-Refugees!

We're looking forward to seeing you!

#b0207 #OpenMeeting
2/2
July 1, 2026 at 3:19 PM
💥Announcement! Thursday 02.07.2026💥

🏳️‍⚧️✊🏾LGBTQIA+ and Female Refugees’ Meeting✊🏾🏳️‍🌈

Thursday, 02.07.2026 | 4.30 pm | Cittipunkt e.V., Brüsseler Straße 36 A, 13353 Berlin

📣 Call to action: asanb.noblogs.org?p=18344 - @women_queer_exchange

#b0207 #OpenMeeting
1/2
July 1, 2026 at 3:18 PM
💥Announcement! Monday 27.04.2026💥

🔥✊🏾Berlin Workplace Struggle: Open Discussion Meeting✊🏾🔥

Monday, 27.04.2026 | 6.30 pm | SZ Aenne Saefkow, Alfredstraße 24, 10365 Berlin

Arrival: U5 Magdalenenstraße | Bus 240 Schottstraße

📣 Call to action: asanb.noblogs.org?p=16935

#b2704 #OpenMeeting
April 26, 2026 at 2:57 PM
Arrival: U1, U3, U8 Kottbusser Tor | Bus 140 Mariannenplatz | Bus M29, 147 Adalbertstraße

#b2304 #OpenMeeting
2/2
April 22, 2026 at 2:47 PM
💥Announcement! Thursday 23.04.2026💥

🔥✊🏾Open gathering: Berlin Architects’ Union✊🏾🔥

Thursday, 23.04.2026 | 7.00 pm | Gecekondu, Kottbusser Tor 10999 Berlin

📣 Call to action: asanb.noblogs.org?p=16805 - @architektinnengewerkschaft

#b2304 #OpenMeeting
1/2
April 22, 2026 at 2:47 PM
💥Announcement! Thursday 23.10.2025💥

🔥✊🏾🇵🇸 Open meeting: Freedom for Palestine, stop the arms industry! 🇵🇸✊🏾🔥

Thursday, 23.10.2025 | 6:30 p.m. | Interbüro Genter Straße 60 13353 Berlin

Arrival: U6, Tram 50, M13, 106, 120 Seestraße

📣 Call: asanb.noblogs.org?p=13680

#b2310 #OpenMeeting
October 21, 2025 at 7:31 PM
Apache OpenMeeting Flaw Allows Server Hijacks and Command Execution - https://cybersecuritynews.com/apache-openmeeting-flaw/
Apache OpenMeeting Flaw Allows Server Hijacks and Command Execution
<p>OpenMeetings is an application that can be used for video calls, collaborative work, and presentations. It can also be added as a plugin to Jira, Confluence or Drupal applications. </p> <p><a href="https://www.sonarsource.com/blog/a-twist-in-the-code-openmeetings-vulnerabilities-through-unexpected-application-state/">Recent reports</a> shared by SonarSource, indicate that a newly discovered vulnerability could allow threat actors to execute commands on the underlying server.</p> <p>Threat actors only need an account that can be created easily on OpenMeetings to exploit this vulnerability. </p> <p>This remote command execution is a combination of Weak Hash, unrestricted access via invitation, and Null-byte injection, leading to the command execution vulnerability.</p> <h2><strong>Apache OpenMeeting Flaw</strong></h2> <p>OpenMeetings enables its users to join a new room when an event is added on the calendar. It also allows users to send an invitation to other users which is done using the Invitation class and setRoom class.</p> <div> <img src="https://lh3.googleusercontent.com/iF9B_hEfrWy3cHVdw7B_0oUcj7Hk4C1Gx0oGXK4Dcu8BRAVShcaUH0-6j9P0NRXRwPteNsgtRrGI-f9A-kxvytVg0ltYzxwi4dyfx5wFe2g-AMd-r2ipdRjrLH3KjVCKFsNsYboKpH5bvolZ1dcRi-8" alt=""><em>Rooms in OpenMeetings (Source: Sonarsource)</em></div> <p>This functionality can be hijacked by threat actors as it has a weak hash using the LIKE operator. This operator allows wildcards to be added as value which results in the attacker getting all the invitation hashes. </p> <div> <img src="https://lh6.googleusercontent.com/8249s5GPXIVkdlmBZJUesO_91Pxr8bkL6GWA_JrL7vQrMej2oCZNOYU5z5QzgYXGeQLavkOv_P30OCqSuu06BvAOuNPnFahef82Q6XCDnm3LQvrdCQPEnhPppyRIf4ZcswEL9x32AzxVFeeaqFYOyBY" alt=""><em>Room invitation sending (Source: Sonarsource)</em></div> <p>Threat actors can enumerate all the valid invitation hashes with this which can be used to gain access to a specific room on behalf of the invited user. However, no other actions can be performed with this. </p> <p>Furthermore, threat actors can create a zombie room by creating an event (which eventually creates a room) and joining the room. While being inside the room, the room can be deleted but sending an invitation from the room functionality still works.</p> <div> <img src="https://lh6.googleusercontent.com/H2uP7n9gQojc57xndfLWKm2EP51j-nFt-X_2xKfEgWjkdbgXbRmRR0TJYQqxb-LPtxGc3soEBl8-hKljqx6e4IO--vxONDAYZDx_Xl4_OzBrU88hWdRb4xv6gjhkqF5z9xjdLKzduZqZqTzRnnPW9c8" alt=""><em>Zombie Room creation (Source: Sonarsource)</em></div> <p>Once they combine the wildcard enumeration and use the invitation functionality to send an invitation to the admin user, administrative rights are gained due to hrights class set empty, resulting in giving the privilege of the invited user.</p> <div> <img src="https://lh3.googleusercontent.com/hjshlFDj0F-jpEXKlDj7rydgUgU3YxwPz6w6oMN5fjsVq4OR7NKHwVCPLBhfv6aKDCau8BqT_BuNVzhtIhJo6PL3hvZGGxHCmqgQjBza1vDg6Ukm-PKwpjcz7jVXR1XF2N9SgW8E24DU-IDQKaHan4Q" alt=""><em>Zombie room + Invitation to the Admin = Administrative Privilege (Source: Sonarsource)</em></div> <p>After performing these activities, the null-byte injection due to the ProcessBuilder executing null-byte in the java realm is OS-specific and implemented in native C. This leads to the threat actor executing arbitrary commands on the underlying server.</p> <h2><strong><a href="https://lists.apache.org/thread/y6vng44c22ll221rtvsv208x1pbjmdoc">CVE-2023-28936</a>: Weak Hash Comparison</strong></h2> <p>This vulnerability exists due to the use of getByHash method that queries the Invitation object from the database by user-provided hash using the LIKE operator that can accept wildcard values resulting in enumeration of all the invite hashes on the OpenMeetings application. This vulnerability is given a CVSS score of 5.3 (<strong>Medium</strong>).</p> <h2><strong><a href="https://lists.apache.org/thread/j2d6mg3rzcphfd8vvvk09d8p4o9lvnqp">CVE-2023-29032</a>: Unrestricted Access via Invitation Hash</strong></h2> <p>This vulnerability exists as the hrights set inherits the invited users rights if no room is identified when being passed to the setUser. This vulnerability was given a CVSS Score of 8.1 (<strong>High</strong>).</p> <h2><strong><a href="https://lists.apache.org/thread/230plvhbdx26m43b0sy942wlwt6kkmmr">CVE-2023-29246</a>: Null-Byte Injection</strong></h2> <p>A threat actor who gains admin privileges on the OpenMeetings can conduct null-byte injection to execute remote code execution on the server. This vulnerability was given a CVSS score of 7.2 (High).</p> <p>Apache has released security patches for this vulnerability and fixed it in the Apache OpenMeetings 7.1.0 version. It is recommended that users upgrade to the latest version of the application to avoid being attacked.</p> <p>The post <a href="https://cybersecuritynews.com/apache-openmeeting-flaw/">Apache OpenMeeting Flaw Allows Server Hijacks and Command Execution</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
cybersecuritynews.com
July 21, 2023 at 4:36 PM