CVE-2008-6508: Path Traversal
Directory traversal vulnerability in the AuthCheck filter in the Admin Console in Openfire 3.6.0a and earlier allows remote attackers to bypass authentication and access the admin interface via a .. (dot dot) in a URI that matches the Exclude-Strings list, as demonstrated by a /setup/setup-/.. sequence in a URI.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-6508?
CVE-2008-6508 is classified as a medium severity vulnerability due to its potential to allow unauthorized access to the admin interface.
How do I fix CVE-2008-6508?
To fix CVE-2008-6508, upgrade your Openfire installation to version 3.6.1 or later where the vulnerability has been addressed.
What systems are affected by CVE-2008-6508?
CVE-2008-6508 affects Openfire versions 3.6.0a and earlier, including specific versions such as 3.2.2, 3.2.3, and 3.5.0.
Can CVE-2008-6508 be exploited remotely?
Yes, CVE-2008-6508 can be exploited remotely, allowing attackers to bypass authentication and access sensitive admin functionality.
What action should I take if I am running an affected version of Openfire?
If you are running an affected version of Openfire, immediately upgrade to the fixed version to secure your environment against this vulnerability.