CVE-2024-54676Disclosure(apache / openmeetings)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache openmeetings systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Default clustering instructions at https://openmeetings.apache.org/Clustering.html  doesn't specify white/black lists for OpenJPA this leads to possible deserialisation of untrusted data. Users are recommended to upgrade to version 8.0.0 and update their startup scripts to include the relevant 'openjpa.serialization.class.blacklist' and 'openjpa.serialization.class.whitelist' configurations as shown in the documentation.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openmeetings

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-26); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
openmeetings

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-26: 3Mentions · 2026-03-27: 1Patch / Workaround · 2026-03-26: 1Technical Details · 2026-03-26: 3Technical Details · 2026-03-27: 103-2603-27
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-03-263
Disclosure2Patch1
2026-03-271
Disclosure1
Full discourse4 posts
  • Nicolas Krassas@Dinosn
    Disclosure

    CVE-2024-54676 — Apache OpenMeetings OpenJPA Deserialization RCE https://blog.securelayer7.net/cve-2024-54676-apache-openmeetings-openjpa-rce/

    Post summary

    The text announces CVE-2024-54676, a deserialization-based remote code execution flaw in Apache OpenMeetings/OpenJPA, and links to a blog post with further details.

    0802383.4K
    153.6K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    『The most significant technical insight from this analysis is the insufficiency of class blacklisting as a defense against deserialization attacks.』 CVE-2024-54676 — Apache OpenMeetings OpenJPA Deserialization RCE https://blog.securelayer7.net/cve-2024-54676-apache-openmeetings-openjpa-rce/

    Post summary

    A blog post discloses CVE‑2024‑54676 for Apache OpenMeetings, highlighting that class blacklisting fails as a defense against deserialization-based RCE attacks.

    00012365
    6.8K followersView on X
  • 보안프로젝트@ngnicky
    Disclosure

    CVE-2024-54676은 Apache OpenMeetings 8.0.0 이전 버전에 영향을 미치는 심각한(CVSS 9.8) Java 역직렬화 취약점입니다. 이 취약점은 인증되지 않은 공격자가 OpenJPA TCPRemoteCommitProvider를 통해 원격 코드 실행을 달성할 수 있도록 합니다. https://blog.securelayer7.net/cve-2024-54676-apache-openmeetings-openjpa-rce/

    Post summary

    The blog post announces a severe Java deserialization vulnerability (CVE‑2024‑54676) in Apache OpenMeetings, which allows unauthenticated attackers to achieve remote code execution via the OpenJPA TCPRemoteCommitProvider.

    00020191
    6.3K followersView on X
  • Mr.Rabbit@01ra66it
    Patch

    CVE-2024-54676は、Apache OpenMeetingsのcluster modeで有効になるOpenJPAのTCPRemoteCommitProviderを悪用する未認証RCE。重要なのは、HTTPではなく生TCP 5636番でJavaデシリアライズが走り、到達できるだけで任意コード実行に至る点。 影響はApache OpenMeetings 8.0.0未満。原因は、TCPRemoteCommitProviderが受信データをObjectInputStream.readObject()でそのまま処理し、認証なし、クラスフィルタなし、シリアライズ許可リストなしで任意オブジェクトを復元してしまうこと。cluster構成で5636/TCPが外部到達可能なら、1回の細工済み接続でRCEに至り得る。 修正は8.0.0で、OpenMeetings本体コードを書き換えるというより、OpenJPAのserialization blacklist/whitelistをJVMオプションで有効化する形。特に custom startup script を使う環境は、更新してもこの設定を反映しないと危険が残る点が注意点。 APT: なし Malware: なし CVE: CVE-2024-54676 IoC: Apache OpenMeetings < 8.0.0, TCP 5636, OpenJPA TCPRemoteCommitProvider, ObjectInputStream.readObject(), cluster mode, commons-beanutils gadget chain, openjpa.serialization.class.blacklist, openjpa.serialization.class.whitelist #CyberSecurity #ThreatIntel #Apache #OpenMeetings #RCE #Deserialization https://blog.securelayer7.net/cve-2024-54676-apache-openmeetings-openjpa-rce/

    Post summary

    The post provides a detailed technical description of an unauthenticated RCE via Java deserialization on Apache OpenMeetings, and it includes specific patch guidance to mitigate the issue in version 8.0.0.

    00010353
    3.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheopenmeetings---

Explore more