CVE-2024-54676

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
08/01/2025
Last modified:
15/01/2025

Description

Vendor: The Apache Software Foundation<br /> <br /> Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0<br /> <br /> Description: Default clustering instructions at https://openmeetings.apache.org/Clustering.html  doesn&amp;#39;t specify white/black lists for OpenJPA this leads to possible deserialisation of untrusted data.<br /> Users are recommended to upgrade to version 8.0.0 and update their startup scripts to include the relevant &amp;#39;openjpa.serialization.class.blacklist&amp;#39; and &amp;#39;openjpa.serialization.class.whitelist&amp;#39; configurations as shown in the documentation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:openmeetings:*:*:*:*:*:*:*:* 2.1 (including) 8.0.0 (excluding)