GHSA-mfjw-x4q4-69p9

Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-mfjw-x4q4-69p9/GHSA-mfjw-x4q4-69p9.json
Aliases
  • CVE-2019-18394
Published
2022-05-24T16:59:50Z
Modified
2022-11-22T20:15:55.861351Z
Details

A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send arbitrary HTTP GET requests. The issue is fixed in version 4.5.0-beta.

References

Affected packages

Maven / org.igniterealtime.openfire:parent

org.igniterealtime.openfire:parent

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0
Fixed
4.5.0-beta

Affected versions

4.*

4.2.0