Nicolas Krassas[verified]@DinosnDisclosure
The text announces CVE-2024-54676, a deserialization-based remote code execution flaw in Apache OpenMeetings/OpenJPA, and links to a blog post with further details.
보안프로젝트[verified]@ngnickyDisclosure
The blog post announces a severe Java deserialization vulnerability (CVE‑2024‑54676) in Apache OpenMeetings, which allows unauthenticated attackers to achieve remote code execution via the OpenJPA TCPRemoteCommitProvider.
Mr.Rabbit[verified]@01ra66itPatch
The post provides a detailed technical description of an unauthenticated RCE via Java deserialization on Apache OpenMeetings, and it includes specific patch guidance to mitigate the issue in version 8.0.0.
Autumn Good@autumn_good_35Disclosure
A blog post discloses CVE‑2024‑54676 for Apache OpenMeetings, highlighting that class blacklisting fails as a defense against deserialization-based RCE attacks.