Issue Details (XML | Word | Printable)

Key: JM-1049
Type: Bug Bug
Status: Closed Closed
Resolution: Fixed
Priority: Critical Critical
Assignee: Gaston Dombiak
Reporter: Derek DeMoro
Votes: 0
Watchers: 0
Operations

If you were logged in you would be able to see more operations.
Openfire (ARCHIVED)

Security fix

Created: 05/03/07 01:22 AM   Updated: 05/26/08 10:44 PM
Component/s: Core
Affects Version/s: 3.3.0
Fix Version/s: 3.3.1

Time Tracking:
Not Specified

Support Plan Customer Issue: No
Resolution Date: 05/11/07 12:42 AM
Acceptance Test - Add?: No


 Description  « Hide
A security issue has been reported that allows malicious users to remotely upload code to Openfire via the built-in admin console. Although there is no known exploit "in the wild", it's highly recommended that users upgrade their server instances to fix this security issue.

Affects: All previous releases of Openfire, at least through Openfire 3.0.0

Workaround: the security issue can be worked around in previous versions of Openfire by limiting access to the admin console port (9090 by default) via firewall rules.



 All   Comments   Work Log   Change History      Sort Order: Ascending order - Click to sort in descending order