CyberSec.Space Logo
Back to CVE Browser

CVE-2019-18394

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0190%
EPSS Percentile39.56th
PublishedOct 24, 2019
Last ModifiedNov 21, 2024

Vulnerability Description

A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send arbitrary HTTP GET requests.

Affected Platforms (CPE)

πŸ“¦
Igniterealtime

Openfire

<= 4.4.2

References & Advisories

Related Vulnerabilities