VulnerabilityModified
CVE-2019-18393
PluginServlet.java in Ignite Realtime Openfire through 4.4.2 does not ensure that retrieved files are located under the Openfire home directory, aka a directory traversal vulnerability.
MEDIUM 5.3EPSS 13.9%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 13.9%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
PluginServlet.java in Ignite Realtime Openfire through 4.4.2 does not ensure that retrieved files are located under the Openfire home directory, aka a directory traversal vulnerability.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 13.94% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- igniterealtime/openfire
- Source
- cve@mitre.org
References
- https://github.com/igniterealtime/Openfire/pull/1498Patch, Third Party Advisory
- https://swarm.ptsecurity.com/openfire-admin-console/
- https://github.com/igniterealtime/Openfire/pull/1498Patch, Third Party Advisory
- https://swarm.ptsecurity.com/openfire-admin-console/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.