Use of Cache Containing Sensitive Information Affecting org.igniterealtime.openfire:xmppserver package, versions [0,]


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.05% (19th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGIGNITEREALTIMEOPENFIRE-6501631
  • published27 Mar 2024
  • disclosed26 Mar 2024
  • creditStavros Manis

Introduced: 26 Mar 2024

CVE-2024-25421  (opens in a new tab)
CWE-524  (opens in a new tab)

How to fix?

A fix was pushed into the master branch but not yet published.

Overview

org.igniterealtime.openfire:xmppserver is an is a XMPP server licensed under the Open Source Apache License.

Affected versions of this package are vulnerable to Use of Cache Containing Sensitive Information due to persistent use of ROOM_CACHE data for usernames after deletion of the associated account. An attacker in possession of a previously used and now deleted username can register that user name to gain access to the chat history of the user until the server is restarted.

CVSS Base Scores

version 3.1