PT-2025-3058 · Apache · Apache Openmeetings

M0D9

·

Published

2025-01-08

·

Updated

2026-03-27

·

CVE-2024-54676

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache OpenMeetings versions 2.1.0 through 8.0.0
Description The default clustering instructions do not specify white/black lists for OpenJPA, leading to possible deserialization of untrusted data. This issue allows attackers to execute arbitrary code in cluster mode. Users are recommended to upgrade to version 8.0.0 and update their startup scripts to include the relevant openjpa.serialization.class.blacklist and openjpa.serialization.class.whitelist configurations.
Recommendations For Apache OpenMeetings versions 2.1.0 through 8.0.0, upgrade to version 8.0.0 and update the startup scripts to include the openjpa.serialization.class.blacklist and openjpa.serialization.class.whitelist configurations as shown in the documentation. As a temporary workaround, consider restricting access to the clustering feature until the issue is resolved.

Fix

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2025-03166
CVE-2024-54676
GHSA-MJF9-4PCV-VFG7

Affected Products

Apache Openmeetings