From f3ade490ddd78146a97dcb21ec15e654b0ae3114 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 2 Aug 2024 21:39:30 +0000 Subject: [PATCH] Publish GHSA-5xvc-rwv8-86p7 --- .../2024/03/GHSA-5xvc-rwv8-86p7/GHSA-5xvc-rwv8-86p7.json | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/advisories/github-reviewed/2024/03/GHSA-5xvc-rwv8-86p7/GHSA-5xvc-rwv8-86p7.json b/advisories/github-reviewed/2024/03/GHSA-5xvc-rwv8-86p7/GHSA-5xvc-rwv8-86p7.json index c015ff91abde2..97d5ea4787e7c 100644 --- a/advisories/github-reviewed/2024/03/GHSA-5xvc-rwv8-86p7/GHSA-5xvc-rwv8-86p7.json +++ b/advisories/github-reviewed/2024/03/GHSA-5xvc-rwv8-86p7/GHSA-5xvc-rwv8-86p7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5xvc-rwv8-86p7", - "modified": "2024-03-27T21:59:21Z", + "modified": "2024-08-02T21:37:54Z", "published": "2024-03-26T21:30:47Z", "aliases": [ "CVE-2024-25420" @@ -9,7 +9,10 @@ "summary": "Ignite Realtime Openfire privilege escalation vulnerability", "details": "An issue in Ignite Realtime Openfire v.4.8.0 and before allows a remote attacker to escalate privileges via the admin.authorizedJIDs system property component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ { @@ -60,6 +63,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-273", "CWE-863" ], "severity": "HIGH",