CVE-2019-18394: Ignite Realtime Openfire
Critical severity, CVSS 9.8. EPSS: 32.3% chance of exploitation in the next 30 days.
A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send arbitrary HTTP GET requests.
Affected products
- Ignite Realtime Openfire: up to and including 4.4.2
Published 2019-10-24. Last modified 2026-06-17.