CVE-2024-25420

An issue in Ignite Realtime Openfire before 4.8.1 allows a remote attacker to escalate privileges via the admin.authorizedJIDs system property component.
Configurations

Configuration 1 (hide)

cpe:2.3:a:igniterealtime:openfire:*:*:*:*:*:*:*:*

History

11 Nov 2025, 14:15

Type Values Removed Values Added
Summary (en) An issue in Ignite Realtime Openfire v.4.9.0 and before allows a remote attacker to escalate privileges via the admin.authorizedJIDs system property component. (en) An issue in Ignite Realtime Openfire before 4.8.1 allows a remote attacker to escalate privileges via the admin.authorizedJIDs system property component.
References
  • () https://github.com/igniterealtime/Openfire/pull/2411 -
  • () https://github.com/igniterealtime/Openfire/releases/tag/v4.8.1 -
  • () https://igniterealtime.atlassian.net/browse/OF-2758 -

Information

Published : 2024-03-26 21:15

Updated : 2025-11-11 14:15


NVD link : CVE-2024-25420

Mitre link : CVE-2024-25420

CVE.ORG link : CVE-2024-25420


JSON object : View

Products Affected

igniterealtime

  • openfire
CWE
CWE-273

Improper Check for Dropped Privileges