GHSA-59h8-h34r-q9cv

Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-59h8-h34r-q9cv/GHSA-59h8-h34r-q9cv.json
Aliases
  • CVE-2019-18393
Published
2022-05-24T16:59:50Z
Modified
2022-11-22T20:13:37.970337Z
Details

PluginServlet.java in Ignite Realtime Openfire through 4.4.2 does not ensure that retrieved files are located under the Openfire home directory, aka a directory traversal vulnerability. Version 4.5.0-beta contains a fix for the issue.

References

Affected packages

Maven / org.igniterealtime.openfire:parent

org.igniterealtime.openfire:parent

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0
Fixed
4.5.0-beta

Affected versions

4.*

4.2.0