Apache OpenMeetings vulnerable to Deserialization of Untrusted Data
Critical severity
GitHub Reviewed
Published
Jan 8, 2025
to the GitHub Advisory Database
•
Updated Jan 8, 2025
Package
Affected versions
>= 2.1.0, < 8.0.0
Patched versions
8.0.0
Description
Published by the National Vulnerability Database
Jan 8, 2025
Published to the GitHub Advisory Database
Jan 8, 2025
Reviewed
Jan 8, 2025
Last updated
Jan 8, 2025
Vendor: The Apache Software Foundation
Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0
Description: Default clustering instructions at https://openmeetings.apache.org/Clustering.html doesn't specify white/black lists for OpenJPA this leads to possible deserialisation of untrusted data.
Users are recommended to upgrade to version 8.0.0 and update their startup scripts to include the relevant 'openjpa.serialization.class.blacklist' and 'openjpa.serialization.class.whitelist' configurations as shown in the documentation.
References