[MAVEN:GHSA-5XVC-RWV8-86P7] Ignite Realtime Openfire privilege escalation vulnerability

Severity High
Affected Packages 1
Fixed Packages 1
CVEs 1

An issue in Ignite Realtime Openfire v.4.8.0 and before allows a remote attacker to escalate privileges via the admin.authorizedJIDs system property component.

Package Affected Version
pkg:maven/org.igniterealtime.openfire/xmppserver < 4.8.1
ID
MAVEN:GHSA-5XVC-RWV8-86P7
Severity
high
URL
https://github.com/advisories/GHSA-5xvc-rwv8-86p7
Published
2024-03-26T21:30:47
(5 months ago)
Modified
2024-03-27T21:59:22
(5 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.igniterealtime.openfire/xmppserver org.igniterealtime.openfire xmppserver < 4.8.1
Fixed pkg:maven/org.igniterealtime.openfire/xmppserver org.igniterealtime.openfire xmppserver = 4.8.1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...