An issue in Ignite Realtime Openfire v.4.9.0 and before allows a remote attacker to escalate privileges via the admin.authorizedJIDs system property component.
The product attempts to drop privileges but does not check or incorrectly checks to see if the drop succeeded.
Link | Tags |
---|---|
https://www.igniterealtime.org/projects/openfire/ | product release notes |
https://github.com/igniterealtime/Openfire/blob/main/xmppserver/src/main/java/org/jivesoftware/openfire/admin/AdminManager.java | product |
https://www.hackthebox.com/blog/openfire-cves-explained-CVE-2024-25420-CVE-2024-25421 | third party advisory exploit |