CVE-2024-54676
Apache OpenMeetings vulnerable to Deserialization of Untrusted Data
Description
Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Default clustering instructions at https://openmeetings.apache.org/Clustering.html doesn't specify white/black lists for OpenJPA this leads to possible deserialisation of untrusted data. Users are recommended to upgrade to version 8.0.0 and update their startup scripts to include the relevant 'openjpa.serialization.class.blacklist' and 'openjpa.serialization.class.whitelist' configurations as shown in the documentation.
How to fix CVE-2024-54676
To remediate CVE-2024-54676, upgrade the affected package to a fixed version below.
- —upgrade to 8.0.0 or later
Is CVE-2024-54676 being exploited?
Likely — EPSS is 65.2%, placing CVE-2024-54676 in the top tier of vulnerabilities by exploitation probability. Prioritise patching.
Affected packages (1)
- >= 2.1.0, < 8.0.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |