CVE-2024-54676
Severity CVSS v4.0:
Pending analysis
Type:
CWE-502
Deserialization of Untrusted Dat
Publication date:
08/01/2025
Last modified:
15/01/2025
Description
Vendor: The Apache Software Foundation<br />
<br />
Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0<br />
<br />
Description: Default clustering instructions at https://openmeetings.apache.org/Clustering.html doesn&#39;t specify white/black lists for OpenJPA this leads to possible deserialisation of untrusted data.<br />
Users are recommended to upgrade to version 8.0.0 and update their startup scripts to include the relevant &#39;openjpa.serialization.class.blacklist&#39; and &#39;openjpa.serialization.class.whitelist&#39; configurations as shown in the documentation.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:apache:openmeetings:*:*:*:*:*:*:*:* | 2.1 (including) | 8.0.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



