CVE-2024-54676
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Jan 8, 2025
Updated: Jan 15, 2025
CWE ID 502
Summary
CVE-2024-54676 is a vulnerability affecting Apache OpenMeetings versions prior to 8.0.0. This vulnerability exists due to the lack of white and black lists for OpenJPA in default clustering instructions, leading to potential deserialization of untrusted data. The Apache Software Foundation recommends users upgrade to version 8.0.0 and update their startup scripts with the 'openjpa.serialization.class.blacklist' and 'openjpa.serialization.class.whitelist' configurations to mitigate this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Apache OpenMeetings
Affected Vendors
- Apache Corporation