AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2024-54676

CRITICAL · CVSS 9.8 EPSS 65.18%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-01-08 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.8. It affects Apache. Its EPSS score suggests a 65.2% probability of exploitation in the next 30 days.

CVE
CVE-2024-54676
Severity
CRITICAL
CVSS
9.8
EPSS
65.18%
Apache

Original NVD Description

Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Default clustering instructions at https://openmeetings.apache.org/Clustering.html  doesn't specify white/black lists for OpenJPA this leads to possible deserialisation of untrusted data. Users are recommended to upgrade to version 8.0.0 and update their startup scripts to include the relevant 'openjpa.serialization.class.blacklist' and 'openjpa.serialization.class.whitelist' configurations as shown in the documentation.

Related CVEs

Other vulnerabilities affecting the same vendor(s)