Description
Openfire is a Jabber server supported by Ignite Realtime. It's a cross-platform Java application, which positions itself as a platform for medium-sized enterprises to control internal communications and make instant messaging easier.
Openfire Admin Console versions before 4.4.3 are vulnerable to a full read SSRF vulnerability in the FaviconServlet. This vulnerability allows an unauthenticated attacker to send arbitrary HTTP GET requests to the internal network and see the responses.
Remediation
Upgrade to the latest version of Openfire (this issue was fixed in version 4.4.3).
References
Related Vulnerabilities
WordPress 4.6.x Multiple Vulnerabilities (4.6 - 4.6.5)
WebLogic Server Side Request Forgery
WordPress Plugin Import all XML, CSV & TXT into WordPress Server-Side Request Forgery (6.5.2)
Seo Panel Server-Side Request Forgery (SSRF) Vulnerability (CVE-2024-22648)
WordPress Plugin Print My Blog-Print, PDF, & eBook Converter Server-Side Request Forgery (1.6.5)