The Igniterealtime.org Community has established a security email address where questions and security vulnerability disclosures may be sent.
Email address: security@igniterealtime.org
The following are a list of previous security disclosures for Ignite Realtime Projects.
| Date | Project - Vulernability | CVE | Jira Ticket | Release Fixed |
|---|---|---|---|---|
| 11 May 2009 | Openfire - Password Change | CVE-2009-1596 | JM-1532 | 3.6.5 |
| 11 May 2009 | Openfire - Changing other User Passwords | CVE-2009-1595 | JM-1531 | 3.6.4 |
| 23 Mar 2009 | Openfire - Open redirect vulnerability in login.jsp | CVE-2008-6511 | ... | 3.6.1 |
| 23 Mar 2009 | Openfire - Cross-site scripting (XSS) vulnerability in login.jsp | CVE-2008-6510 | ... | 3.6.1 |
| 23 Mar 2009 | Openfire - SQL Injection | CVE-2008-6509 | ... | 3.6.1 |
| 23 Mar 2009 | Openfire - Directory traversal vulnerability in the AuthCheck filter | CVE-2008-6508 | ... | 3.6.1 |
| 10 Feb 2009 | Openfire - Directory traversal vulnerability in log.jsp | CVE-2009-0497 | ... | 3.6.3 |
| 10 Feb 2009 | Openfire - Multiple cross-site scripting (XSS) vulnerabilities | CVE-2009-0496 | ... | 3.6.3 |
| 11 Apr 2008 | Openfire - Denial of service (daemon outage) in ConnectionManagerImpl.java | CVE-2008-1728 | ... | 3.5.0 |
| 1 Jun 2007 | Openfire - Unauthorized access through DWR | CVE-2007-2975 | ... | 3.3.2 |