Critical severity9.8NVD Advisory· Published Jan 8, 2025· Updated Jun 17, 2026
CVE-2024-54676
CVE-2024-54676
Description
Vendor: The Apache Software Foundation
Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0
Description: Default clustering instructions at https://openmeetings.apache.org/Clustering.html doesn't specify white/black lists for OpenJPA this leads to possible deserialisation of untrusted data. Users are recommended to upgrade to version 8.0.0 and update their startup scripts to include the relevant 'openjpa.serialization.class.blacklist' and 'openjpa.serialization.class.whitelist' configurations as shown in the documentation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.openmeetings:openmeetings-parentMaven | >= 2.1.0, < 8.0.0 | 8.0.0 |
Affected products
3cpe:2.3:a:apache:openmeetings:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:apache:openmeetings:*:*:*:*:*:*:*:*range: >=2.1,<8.0.0
- (no CPE)range: 2.1
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-mjf9-4pcv-vfg7ghsaADVISORY
- lists.apache.org/thread/o0k05jxrt5tp4nm45lj14yfjxmg67m95nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2024-54676ghsaADVISORY
- www.openwall.com/lists/oss-security/2025/01/08/1nvdMailing ListWEB
- github.com/apache/openmeetings/commit/1c3426c6d3abbd984a3c01a61decf1242ea38923ghsaWEB
- issues.apache.org/jira/browse/OPENMEETINGS-2787ghsaWEB
News mentions
0No linked articles in our index yet.