CVE-2024-54676
CRITICALApache OpenMeetings 2.1.0-8.0.0 - Deserialization of Untrusted Data via OpenJPA Configuration
Title source: llmDescription
Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Default clustering instructions at https://openmeetings.apache.org/Clustering.html doesn't specify white/black lists for OpenJPA this leads to possible deserialisation of untrusted data. Users are recommended to upgrade to version 8.0.0 and update their startup scripts to include the relevant 'openjpa.serialization.class.blacklist' and 'openjpa.serialization.class.whitelist' configurations as shown in the documentation.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
https://lists.apache.org/thread/o0k05jxrt5tp4nm45lj14yfjxmg67m95
Scores
CVSS v3
9.8
EPSS
0.0459
EPSS Percentile
89.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-502
Status
published
Products (2)
apache/openmeetings
2.1 - 8.0.0
org.apache.openmeetings/openmeetings-parent
2.1.0 - 8.0.0Maven
Published
Jan 08, 2025
Tracked Since
Feb 18, 2026