Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Default clustering instructions at https://openmeetings.apache.org/Clustering.html  doesn't specify white/black lists for OpenJPA this leads to possible deserialisation of untrusted data. Users are recommended to upgrade to version 8.0.0 and update their startup scripts to include the relevant 'openjpa.serialization.class.blacklist' and 'openjpa.serialization.class.whitelist' configurations as shown in the documentation.
History

Wed, 15 Jan 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache openmeetings
CPEs cpe:2.3:a:apache:openmeetings:*:*:*:*:*:*:*:*
Vendors & Products Apache
Apache openmeetings

Thu, 09 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 08 Jan 2025 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 08 Jan 2025 09:30:00 +0000

Type Values Removed Values Added
References

Wed, 08 Jan 2025 08:45:00 +0000

Type Values Removed Values Added
Description Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Default clustering instructions at https://openmeetings.apache.org/Clustering.html  doesn't specify white/black lists for OpenJPA this leads to possible deserialisation of untrusted data. Users are recommended to upgrade to version 8.0.0 and update their startup scripts to include the relevant 'openjpa.serialization.class.blacklist' and 'openjpa.serialization.class.whitelist' configurations as shown in the documentation.
Title Apache OpenMeetings: Deserialisation of untrusted data in cluster mode
Weaknesses CWE-502
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2025-01-08T08:40:03.705Z

Updated: 2025-01-08T14:00:52.923Z

Reserved: 2024-12-05T04:43:41.354Z

Link: CVE-2024-54676

cve-icon Vulnrichment

Updated: 2025-01-08T09:02:51.250Z

cve-icon NVD

Status : Analyzed

Published: 2025-01-08T09:15:07.440

Modified: 2025-01-15T15:50:39.987

Link: CVE-2024-54676

cve-icon Redhat

No data.