Vendor: The Apache Software Foundation
Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0
Description: Default clustering instructions at https://openmeetings.apache.org/Clustering.html doesn't specify white/black lists for OpenJPA this leads to possible deserialisation of untrusted data.
Users are recommended to upgrade to version 8.0.0 and update their startup scripts to include the relevant 'openjpa.serialization.class.blacklist' and 'openjpa.serialization.class.whitelist' configurations as shown in the documentation.
References
Link | Resource |
---|---|
http://www.openwall.com/lists/oss-security/2025/01/08/1 | Mailing List |
https://lists.apache.org/thread/o0k05jxrt5tp4nm45lj14yfjxmg67m95 | Vendor Advisory |
Configurations
History
15 Jan 2025, 15:50
Type | Values Removed | Values Added |
---|---|---|
First Time |
Apache
Apache openmeetings |
|
CPE | cpe:2.3:a:apache:openmeetings:*:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
References | () http://www.openwall.com/lists/oss-security/2025/01/08/1 - Mailing List | |
References | () https://lists.apache.org/thread/o0k05jxrt5tp4nm45lj14yfjxmg67m95 - Vendor Advisory |
08 Jan 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
CWE |
08 Jan 2025, 09:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-08 09:15
Updated : 2025-01-15 15:50
NVD link : CVE-2024-54676
Mitre link : CVE-2024-54676
JSON object : View
Products Affected
apache
- openmeetings
CWE
No CWE.