Openfire LFI

Published on 01 Oct 2021
Vulnerability

Ignite Realtime supports Openfire, a Jabber server. It’s a Java program that serves as a platform for medium-sized businesses to manage internal communications and make instant messaging more convenient. The FaviconServlet in earlier versions of the Openfire Admin Console is vulnerable to a full read SSRF vulnerability. Attackers can use this vulnerability to send arbitrary HTTP GET queries to the internal network and view the responses.

Mitigation / Precaution

We suggest that you upgrade to the most recent version.

Anandhu Krishnan
Written by
Lead Engineer

Anandhu is an accomplished Senior Lead Engineer with a strong focus on back-end development. His expertise lies in architecting and optimizing the core of software applications to ensure they run smoothly and efficiently. With a meticulous attention to detail and a deep understanding of data management and server-side operations, Anandhu has been a driving force behind the success of various back-end projects.

Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 14 days
4.8 on G2 • ISO 27001 certified
See How Beagle Security Works
No credit card • No setup required
Launch interactive demo