Vendor: The Apache Software Foundation
Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0
Description: Default clustering instructions at https://openmeetings.apache.org/Clustering.html doesn't specify white/black lists for OpenJPA this leads to possible deserialisation of untrusted data.
Users are recommended to upgrade to version 8.0.0 and update their startup scripts to include the relevant 'openjpa.serialization.class.blacklist' and 'openjpa.serialization.class.whitelist' configurations as shown in the documentation.
References
Link | Resource |
---|---|
https://lists.apache.org/thread/o0k05jxrt5tp4nm45lj14yfjxmg67m95 | Vendor Advisory |
http://www.openwall.com/lists/oss-security/2025/01/08/1 | Mailing List |
Configurations
History
15 Jan 2025, 15:50
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:apache:openmeetings:*:*:*:*:*:*:*:* | |
First Time |
Apache openmeetings
Apache |
|
References | () https://lists.apache.org/thread/o0k05jxrt5tp4nm45lj14yfjxmg67m95 - Vendor Advisory | |
References | () http://www.openwall.com/lists/oss-security/2025/01/08/1 - Mailing List |
08 Jan 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
08 Jan 2025, 09:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-08 09:15
Updated : 2025-01-15 15:50
NVD link : CVE-2024-54676
Mitre link : CVE-2024-54676
CVE.ORG link : CVE-2024-54676
JSON object : View
Products Affected
apache
- openmeetings
CWE
CWE-502
Deserialization of Untrusted Data