GHSA-mfjw-x4q4-69p9

Source
https://github.com/advisories/GHSA-mfjw-x4q4-69p9
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-mfjw-x4q4-69p9/GHSA-mfjw-x4q4-69p9.json
Aliases
Published
2022-05-24T16:59:50Z
Modified
2023-11-08T04:01:25.782205Z
Details

A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send arbitrary HTTP GET requests. The issue is fixed in version 4.5.0-beta.

References

Affected packages

Maven / org.igniterealtime.openfire:parent

Package

Name
org.igniterealtime.openfire:parent

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
4.5.0-beta

Affected versions

4.*

4.2.0