Vendor: The Apache Software Foundation
Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0
Description: Default clustering instructions at https://openmeetings.apache.org/Clustering.html doesn't specify white/black lists for OpenJPA this leads to possible deserialisation of untrusted data.
Users are recommended to upgrade to version 8.0.0 and update their startup scripts to include the relevant 'openjpa.serialization.class.blacklist' and 'openjpa.serialization.class.whitelist' configurations as shown in the documentation.
Metrics
Affected Vendors & Products
References
History
Wed, 15 Jan 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apache
Apache openmeetings |
|
CPEs | cpe:2.3:a:apache:openmeetings:*:*:*:*:*:*:*:* | |
Vendors & Products |
Apache
Apache openmeetings |
Thu, 09 Jan 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 08 Jan 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Wed, 08 Jan 2025 09:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Wed, 08 Jan 2025 08:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Default clustering instructions at https://openmeetings.apache.org/Clustering.html doesn't specify white/black lists for OpenJPA this leads to possible deserialisation of untrusted data. Users are recommended to upgrade to version 8.0.0 and update their startup scripts to include the relevant 'openjpa.serialization.class.blacklist' and 'openjpa.serialization.class.whitelist' configurations as shown in the documentation. | |
Title | Apache OpenMeetings: Deserialisation of untrusted data in cluster mode | |
Weaknesses | CWE-502 | |
References |
|
MITRE
Status: PUBLISHED
Assigner: apache
Published: 2025-01-08T08:40:03.705Z
Updated: 2025-01-08T14:00:52.923Z
Reserved: 2024-12-05T04:43:41.354Z
Link: CVE-2024-54676
Vulnrichment
Updated: 2025-01-08T09:02:51.250Z
NVD
Status : Analyzed
Published: 2025-01-08T09:15:07.440
Modified: 2025-01-15T15:50:39.987
Link: CVE-2024-54676
Redhat
No data.