Openfire Full Read SSRF

Published on 16 Jun 2021
Vulnerability

Openfire, a Jabber portal assisted by Ignite Realtime. It is a Java application that works through many platforms. It is a network for small companies that allows them to monitor private communications and make immediate messaging more convenient. Versions of the Openfire Admin Console prior to 4.4.3 are subject to a full read SSRF flaw in the FaviconServlet. Unauthenticated attackers can exploit this flaw by sending arbitrary HTTP GET requests to the corporate network and obtaining full-sized outputs from the intended web services.

Mitigation / Precaution

  • Update Openfire to the most recent patch (This problem was resolved in version 4.4.3).
Prathap
Written by
Co-founder, Director

Prathap has around 20 years of experience and has worked on various projects in leading companies like Hitachi, Toshiba, Schneider Electric, ABB, Panasonic, and MicroFuzzy. His expertise lies in architecting, designing, and developing secure projects covering various aspects of software development, processes, and methodology.

Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 14 days
4.8 on G2 • ISO 27001 certified
See How Beagle Security Works
No credit card • No setup required
Launch interactive demo