Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h5m2-8pmw-gmg7

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Ignite Realtime Openfire before 3.6.5 does not properly implement the register.password (aka canChangePassword) console configuration setting, which allows remote authenticated users to bypass intended policy and change their own passwords via a passwd_change IQ packet.

Ignite Realtime Openfire before 3.6.5 does not properly implement the register.password (aka canChangePassword) console configuration setting, which allows remote authenticated users to bypass intended policy and change their own passwords via a passwd_change IQ packet.

EPSS

Процентиль: 57%
0.00351
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 6.5
nvd
больше 16 лет назад

Ignite Realtime Openfire before 3.6.5 does not properly implement the register.password (aka canChangePassword) console configuration setting, which allows remote authenticated users to bypass intended policy and change their own passwords via a passwd_change IQ packet.

EPSS

Процентиль: 57%
0.00351
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-287