Apache OpenMeetings: Deserialisation of untrusted data in cluster mode
Vulnerability Description
Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Default clustering instructions at https://openmeetings.apache.org/Clustering.html doesn't specify white/black lists for OpenJPA this leads to possible deserialisation of untrusted data. Users are recommended to upgrade to version 8.0.0 and update their startup scripts to include the relevant 'openjpa.serialization.class.blacklist' and 'openjpa.serialization.class.whitelist' configurations as shown in the documentation.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-54676
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- m0d9 from Tencent Yunding Lab
More from Apache Software Foundation
View All →Affected Vendor
Apache Software Foundation
View all reports →