endor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Default clustering instructions at https://openmeetings.apache.org/Clustering.html doesn't specify white/black lists for OpenJPA this leads to possible deserialisation of untrusted data. Users are recommended to upgrade to version 8.0.0 and update their startup scripts to include the relevant 'openjpa.serialization.class.blacklist' and 'openjpa.serialization.class.whitelist' configurations as shown in the documentation.
| Link | Resource |
|---|---|
| https://lists.apache.org/thread/o0k05jxrt5tp4nm45lj14yfjxmg67m95 | Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2025/01/08/1 | Mailing List |
15 Jan 2025, 15:50
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Apache
Apache openmeetings |
|
| CPE | cpe:2.3:a:apache:openmeetings:*:*:*:*:*:*:*:* | |
| References | () https://lists.apache.org/thread/o0k05jxrt5tp4nm45lj14yfjxmg67m95 - Vendor Advisory | |
| References | () http://www.openwall.com/lists/oss-security/2025/01/08/1 - Mailing List |
08 Jan 2025, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| Summary |
|
08 Jan 2025, 09:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Published : 2025-01-08 09:15
Updated : 2025-01-15 15:50
NVD link : CVE-2024-54676
Mitre link : CVE-2024-54676
CVE.ORG link : CVE-2024-54676
JSON object : View
Deserialization of Untrusted Data