CVE-2024-25421: Critical severity openfire vulnerability
Published Mar 26, 2024
·Updated
An issue in Ignite Realtime Openfire v.4.8.0 and before allows a remote attacker to escalate privileges via the ROOMCACHE component.
Other sources
An issue in Ignite Realtime Openfire v.4.9.0 and before allows a remote attacker to escalate privileges via the ROOMCACHE component.
— MITRE
Affected Software
2 affected componentsFixes available
maven/org.igniterealtime.openfire:xmppserver<4.8.1
4.8.1
igniterealtime Openfire<=4.9.0
Event History
Mar 26, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
Description
Data Sourced
via NVD·09:15 PM
SeverityWeakness
Advisory Published
via GitHub·09:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-25421?
CVE-2024-25421 has a high severity rating due to its ability to allow remote attackers to escalate privileges.
2
How do I fix CVE-2024-25421?
To fix CVE-2024-25421, upgrade Openfire to version 4.8.1 or later.
3
Which versions of Openfire are affected by CVE-2024-25421?
CVE-2024-25421 affects Openfire versions 4.8.0 and before, as well as 4.9.0 and before.
4
What component is exploited in CVE-2024-25421?
CVE-2024-25421 exploits the ROOM_CACHE component to escalate privileges.
5
Can CVE-2024-25421 affect my Openfire installation?
If you are using Openfire version 4.9.0 or earlier, your installation is vulnerable to CVE-2024-25421.