CVE-2019-18394: SSRF
Published Oct 24, 2019
·Updated
A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send arbitrary HTTP GET requests.
Affected Software
1 affected component
igniterealtime Openfire<=4.4.2
Remediation
Patch Available
Event History
Oct 24, 2019
CVE Published
via MITRE·10:58 AM
Data Sourced
via MITRE·10:58 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-18394?
CVE-2019-18394 has been assigned a medium severity rating due to its potential for impact on the application and data.
2
How do I fix CVE-2019-18394?
To fix CVE-2019-18394, upgrade Openfire to version 4.4.3 or later, where the vulnerability has been addressed.
3
What systems are affected by CVE-2019-18394?
CVE-2019-18394 affects Ignite Realtime Openfire versions up to and including 4.4.2.
4
What type of vulnerability is CVE-2019-18394?
CVE-2019-18394 is classified as a Server Side Request Forgery (SSRF) vulnerability.
5
How can attackers exploit CVE-2019-18394?
Attackers can exploit CVE-2019-18394 by sending arbitrary HTTP GET requests, potentially compromising internal systems.