QID 996951
Date Published: 2024-01-29
QID 996951: Java (Maven) Security Update for org.igniterealtime.openfire:parent (GHSA-r62w-x9pp-jrqp)
The jabber:iq:auth implementation in IQAuthHandler.java in Ignite Realtime Openfire before 3.6.4 allows remote authenticated users to change the passwords of arbitrary accounts via a modified username element in a passwd_change action.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-r62w-x9pp-jrqp for updates and patch information.
Vendor References
- GHSA-r62w-x9pp-jrqp -
github.com/advisories/GHSA-r62w-x9pp-jrqp
CVEs related to QID 996951
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-r62w-x9pp-jrqp | org.igniterealtime.openfire:parent |
|