目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1000

100.0%
获取后续新漏洞提醒登录后订阅
一、 漏洞 CVE-2023-32315 基础信息
漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Openfire administration console authentication bypass
来源: 美国国家漏洞数据库 NVD
Vulnerability Description
Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based application, was found to be vulnerable to a path traversal attack via the setup environment. This permitted an unauthenticated user to use the unauthenticated Openfire Setup Environment in an already configured Openfire environment to access restricted pages in the Openfire Admin Console reserved for administrative users. This vulnerability affects all versions of Openfire that have been released since April 2015, starting with version 3.10.0. The problem has been patched in Openfire release 4.7.5 and 4.6.8, and further improvements will be included in the yet-to-be released first version on the 4.8 branch (which is expected to be version 4.8.0). Users are advised to upgrade. If an Openfire upgrade isn’t available for a specific release, or isn’t quickly actionable, users may see the linked github advisory (GHSA-gw42-f939-fhvm) for mitigation advice.
来源: 美国国家漏洞数据库 NVD
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
来源: 美国国家漏洞数据库 NVD
Vulnerability Type
对路径名的限制不恰当(路径遍历)
来源: 美国国家漏洞数据库 NVD
Vulnerability Title
Ignite Realtime Openfire 路径遍历漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Ignite Realtime Openfire是Ignite Realtime社区的一款采用Java开发且基于XMPP(前称Jabber,即时通讯协议)的跨平台开源实时协作(RTC)服务器。它能够构建高效率的即时通信服务器,并支持上万并发用户数量。 Ignite Realtime Openfire 存在安全漏洞,该漏洞源于允许未经身份验证的用户在已配置的 Openfire 环境中使用未经身份验证的 Openfire 设置环境,以访问为管理用户保留的 Openfire 管理控制台中的受限页面,以下产品和版
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD
受影响产品
厂商产品影响版本CPE订阅
igniterealtimeOpenfire >= 3.10.0, < 4.6.8 -
二、漏洞 CVE-2023-32315 的公开POC
#POC 描述源链接神龙链接
1Nonehttps://github.com/ohnonoyesyes/CVE-2023-32315POC详情
2rcehttps://github.com/tangxiaofeng7/CVE-2023-32315-Openfire-BypassPOC详情
3Nonehttps://github.com/5rGJ5aCh5oCq5YW9/CVE-2023-32315expPOC详情
4Openfire Console Authentication Bypass Vulnerability with RCE pluginhttps://github.com/miko550/CVE-2023-32315POC详情
5Perform With Massive Openfire Unauthenticated Usershttps://github.com/ThatNotEasy/CVE-2023-32315POC详情
6CVE-2023-32315-Openfire-Bypasshttps://github.com/izzz0/CVE-2023-32315-POCPOC详情
7Tool for CVE-2023-32315 exploitationhttps://github.com/gibran-abdillah/CVE-2023-32315POC详情
8Openfire未授权到RCE(CVE-2023-32315)复现https://github.com/CN016/Openfire-RCE-CVE-2023-32315-POC详情
9A PoC exploit for CVE-2023-32315 - Openfire Authentication Bypasshttps://github.com/K3ysTr0K3R/CVE-2023-32315-EXPLOITPOC详情
10Nonehttps://github.com/bryanqb07/CVE-2023-32315POC详情
11Nonehttps://github.com/asepsaepdin/CVE-2023-32315POC详情
12Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based application, was found to be vulnerable to a path traversal attack via the setup environment. This permitted an unauthenticated user to use the unauthenticated Openfire Setup Environment in an already configured Openfire environment to access restricted pages in the Openfire Admin Console reserved for administrative users. This vulnerability affects all versions of Openfire that have been released since April 2015, starting with version 3.10.0. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-32315.yamlPOC详情
13Nonehttps://github.com/Threekiii/Awesome-POC/blob/master/%E4%B8%AD%E9%97%B4%E4%BB%B6%E6%BC%8F%E6%B4%9E/Openfire%E7%AE%A1%E7%90%86%E5%90%8E%E5%8F%B0%E8%AE%A4%E8%AF%81%E7%BB%95%E8%BF%87%E6%BC%8F%E6%B4%9E%20CVE-2023-32315.mdPOC详情
14https://github.com/vulhub/vulhub/blob/master/openfire/CVE-2023-32315/README.mdPOC详情
15Nonehttps://github.com/pulentoski/Explotacion-CVE-2023-32315-OpenfirePOC详情
16CVE-2023-32315(java7)https://github.com/shiyingzhencai/CVE-2023-32315-java7-POC详情
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC
三、漏洞 CVE-2023-32315 的情报信息
Please 登录 to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2023-32315

暂无评论


发表评论