Description
Openfire is a Jabber server supported by Ignite Realtime. It's a cross-platform Java application, which positions itself as a platform for medium-sized enterprises to control internal communications and make instant messaging easier.
Openfire Admin Console versions before 4.4.3 are vulnerable to a full read SSRF vulnerability in the FaviconServlet. This vulnerability allows an unauthenticated attacker to send arbitrary HTTP GET requests to the internal network and see the responses.
Remediation
Upgrade to the latest version of Openfire (this issue was fixed in version 4.4.3).
References
Related Vulnerabilities
WordPress Server-Side Request Forgery (SSRF) Vulnerability (CVE-2019-17670)
WordPress Plugin Craw Data Server-Side Request Forgery (1.0.0)
WordPress 4.1.x Multiple Vulnerabilities (4.1 - 4.1.27)
WordPress Plugin Import all XML, CSV & TXT into WordPress Server-Side Request Forgery (6.5.2)
WordPress Plugin Web Stories Server-Side Request Forgery (1.24.0)