HIGH🇵🇱 Wersja polska

CVE-2024-25420

CVSS 7.2v3.1pub. 2024-03-26upd. 2025-11-11

An issue in Ignite Realtime Openfire before 4.8.1 allows a remote attacker to escalate privileges via the admin.authorizedJIDs system property component.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • Igniterealtime Openfire

    APP
    Igniterealtime
    ≤ 4.9.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
LPE
CWE
References

Related vulnerabilities

CVE-2024-25421CRITICAL9.8PL ✓same product

Privilege escalation w Ignite Realtime Openfire przez komponent ROOM_CACHE

CVE-2021-45967CRITICAL9.8PL ✓same product

Path traversal w Pascom Cloud Phone System przez błąd konfiguracji NGINX/Tomcat

CVE-2019-18394CRITICAL9.8PL ✓same product

SSRF w Ignite Realtime Openfire — dowolne żądania HTTP GET

CVE-2023-32315HIGH8.6⚠ KEVsame product

Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a...

CVE-2014-3451HIGH7.5same product

OpenFire XMPP Server before 3.10 accepts self-signed certificates, which allows remote attackers to perform un...