Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS02cHdnLWdnNmotNWNybc4AA6UB
Ignite Realtime Openfire privilege escalation vulnerability
An issue in Ignite Realtime Openfire v.4.8.0 and before allows a remote attacker to escalate privileges via the ROOM_CACHE component.
Permalink: https://github.com/advisories/GHSA-6pwg-gg6j-5crmJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02cHdnLWdnNmotNWNybc4AA6UB
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: 8 months ago
Updated: 8 months ago
Identifiers: GHSA-6pwg-gg6j-5crm, CVE-2024-25421
References:
- https://nvd.nist.gov/vuln/detail/CVE-2024-25421
- https://github.com/igniterealtime/Openfire/blob/main/xmppserver/src/main/java/org/jivesoftware/openfire/muc/spi/LocalMUCRoomManager.java
- https://www.hackthebox.com/blog/openfire-cves-explained-CVE-2024-25420-CVE-2024-25421
- https://www.igniterealtime.org/projects/openfire
- https://github.com/igniterealtime/Openfire/commit/d66bddd29dbf56aa9b822635619fa66cca6f2112
- https://github.com/advisories/GHSA-6pwg-gg6j-5crm
Blast Radius: 0.0
Affected Packages
maven:org.igniterealtime.openfire:xmppserver
Dependent packages: 3Dependent repositories: 33
Downloads:
Affected Version Ranges: < 4.8.1
Fixed in: 4.8.1
All affected versions: 4.2.0
All unaffected versions: