PT-2019-5532 · Ignite Realtime · Openfire

Alexandr Shvetsov

·

Publicado

2019-10-03

·

Atualizado

2022-05-24

·

CVE-2019-18393

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Openfire versions 4.4.2 and earlier
Description The issue is related to a directory traversal vulnerability in the PluginServlet.java file. This vulnerability exists due to incorrect path name restrictions to a directory with limited access. Exploitation of the vulnerability may allow a remote attacker to impact the confidentiality of protected information.
Recommendations For Openfire versions 4.4.2 and earlier, update to version 4.5.0-beta or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and directories under the Openfire home directory to minimize the risk of exploitation.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-03826
CVE-2019-18393
GHSA-59H8-H34R-Q9CV

Produtos afetados

Openfire