{ "id": "CVE-2024-25420", "sourceIdentifier": "cve@mitre.org", "published": "2024-03-26T21:15:52.710", "lastModified": "2024-03-27T12:29:30.307", "vulnStatus": "Awaiting Analysis", "descriptions": [ { "lang": "en", "value": "An issue in Ignite Realtime Openfire v.4.9.0 and before allows a remote attacker to escalate privileges via the admin.authorizedJIDs system property component." }, { "lang": "es", "value": "Un problema en Ignite Realtime Openfire v.4.9.0 y anteriores permite a un atacante remoto escalar privilegios a trav\u00e9s del componente de propiedad del sistema admin.authorizedJIDs." } ], "metrics": {}, "references": [ { "url": "https://github.com/igniterealtime/Openfire/blob/main/xmppserver/src/main/java/org/jivesoftware/openfire/admin/AdminManager.java", "source": "cve@mitre.org" }, { "url": "https://www.hackthebox.com/blog/openfire-cves-explained-CVE-2024-25420-CVE-2024-25421", "source": "cve@mitre.org" }, { "url": "https://www.igniterealtime.org/projects/openfire/", "source": "cve@mitre.org" } ] }