• Home

    Email

    Github

    Donate

  • jamesbrine.com.au

CVE-2024-25420 Information

Mar 27, 2024 cve

Description

An issue in Ignite Realtime Openfire v.4.9.0 and before allows a remote attacker to escalate privileges via the admin.authorizedJIDs system property component.

Reference

https://www.igniterealtime.org/projects/openfire/ https://github.com/igniterealtime/Openfire/blob/main/xmppserver/src/main/java/org/jivesoftware/openfire/admin/AdminManager.java https://www.hackthebox.com/blog/openfire-cves-explained-CVE-2024-25420-CVE-2024-25421

  • 𝖏𝖆𝖒𝖊𝖘𝖇𝖗𝖎𝖓𝖊.𝖈𝖔𝖒.𝖆𝖚