OpenFire XMPP Server before 3.10 accepts self-signed certificates, which allows remote attackers to perform unspecified spoofing attacks.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NIgniterealtime Openfire
APPIgniterealtime≤ 3.9.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References
Related vulnerabilities
CVE-2024-25421CRITICAL9.8PL ✓same product
Privilege escalation w Ignite Realtime Openfire przez komponent ROOM_CACHE
CVE-2021-45967CRITICAL9.8PL ✓same product
Path traversal w Pascom Cloud Phone System przez błąd konfiguracji NGINX/Tomcat
CVE-2019-18394CRITICAL9.8PL ✓same product
SSRF w Ignite Realtime Openfire — dowolne żądania HTTP GET
CVE-2023-32315HIGH8.6⚠ KEVsame product
Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a...
CVE-2024-25420HIGH7.2same product
An issue in Ignite Realtime Openfire before 4.8.1 allows a remote attacker to escalate privileges via the admi...