CVE-2009-1595

EPSS 8.8%

Ignite Realtime Openfire Allows Users to Change Passwords of Arbitrary Accounts

Published: 5/2/2022Modified: 1/23/2024
Also known as:GHSA-r62w-x9pp-jrqp

Description

The `jabber:iq:auth` implementation in `IQAuthHandler.java` in Ignite Realtime Openfire before 3.6.4 allows remote authenticated users to change the passwords of arbitrary accounts via a modified username element in a `passwd_change` action.

Affected packages (1)

References (8)