An issue in Ignite Realtime Openfire before 4.8.1 allows a remote attacker to escalate privileges via the admin.authorizedJIDs system property component.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HIgniterealtime Openfire
APPIgniterealtime≤ 4.9.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
LPE
CWE
References
Related vulnerabilities
CVE-2024-25421CRITICAL9.8PL ✓same product
Privilege escalation w Ignite Realtime Openfire przez komponent ROOM_CACHE
CVE-2021-45967CRITICAL9.8PL ✓same product
Path traversal w Pascom Cloud Phone System przez błąd konfiguracji NGINX/Tomcat
CVE-2019-18394CRITICAL9.8PL ✓same product
SSRF w Ignite Realtime Openfire — dowolne żądania HTTP GET
CVE-2023-32315HIGH8.6⚠ KEVsame product
Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a...
CVE-2014-3451HIGH7.5same product
OpenFire XMPP Server before 3.10 accepts self-signed certificates, which allows remote attackers to perform un...