PT-2025-3058 · Apache · Apache Openmeetings
M0D9
·
Published
2025-01-08
·
Updated
2026-03-27
·
CVE-2024-54676
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apache OpenMeetings versions 2.1.0 through 8.0.0
Description
The default clustering instructions do not specify white/black lists for OpenJPA, leading to possible deserialization of untrusted data. This issue allows attackers to execute arbitrary code in cluster mode. Users are recommended to upgrade to version 8.0.0 and update their startup scripts to include the relevant
openjpa.serialization.class.blacklist and openjpa.serialization.class.whitelist configurations.Recommendations
For Apache OpenMeetings versions 2.1.0 through 8.0.0, upgrade to version 8.0.0 and update the startup scripts to include the
openjpa.serialization.class.blacklist and openjpa.serialization.class.whitelist configurations as shown in the documentation.
As a temporary workaround, consider restricting access to the clustering feature until the issue is resolved.Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Openmeetings