Vulnerability record · CVE-2023-32315 · published 26 May 2023
CVE-2023-32315: Openfire admin console path traversal allows unauthenticated access
Igniterealtime · Openfire
Openfire's web-based administrative console is vulnerable to a path traversal flaw reachable through the unauthenticated Setup Environment. On an already-configured server, an unauthenticated attacker can use that setup endpoint to reach Admin Console pages reserved for administrators. It affects Openfire releases from 3.10.0 onward and is patched in 4.7.5 and 4.6.8.
Description
Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based application, was found to be vulnerable to a path traversal attack via the setup environment. This permitted an unauthenticated user to use the unauthenticated Openfire Setup Environment in an already configured Openfire environment to access restricted pages in the Openfire Admin Console reserved for administrative users. This vulnerability affects all versions of Openfire that have been released since April 2015, starting with version 3.10.0. The problem has been patched in Openfire release 4.7.5 and 4.6.8, and further improvements will be included in the yet-to-be released first version on the 4.8 branch (which is expected to be version 4.8.0). Users are advised to upgrade. If an Openfire upgrade isn’t available for a specific release, or isn’t quickly actionable, users may see the linked github advisory (GHSA-gw42-f939-fhvm) for mitigation advice.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
critical priorityIt is in CISA KEV with a near-maximum EPSS score, requires no authentication, and public exploit material is referenced.
What it is
Openfire's web-based administrative console is vulnerable to a path traversal flaw reachable through the unauthenticated Setup Environment. On an already-configured server, an unauthenticated attacker can use that setup endpoint to reach Admin Console pages reserved for administrators. It affects Openfire releases from 3.10.0 onward and is patched in 4.7.5 and 4.6.8.
Impact
An attacker gains access to administrative-only console pages without credentials, exposing sensitive configuration and management functionality. The CVSS vector rates confidentiality impact as high with no integrity or availability impact.
Attack surface
Reachable over the network via HTTP against the Openfire Admin Console setup environment; no authentication and no user interaction are required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). The description states the setup environment is used to access restricted admin pages.
Exploitation
Listed in CISA KEV with a due date of 2023-09-14, and EPSS probability is 0.99999 (percentile 0.99992). References are tagged Exploit, including a Packet Storm entry titled Authentication Bypass Remote Code Execution, indicating public exploit material exists.
What to do
- Upgrade Openfire to 4.7.5 or 4.6.8 (or the 4.8.0 branch when available).
- If upgrade is not immediately possible, apply the mitigation guidance in vendor advisory GHSA-gw42-f939-fhvm.
- Restrict network access to the Openfire Admin Console and setup environment to trusted management networks only.
- Discontinue use of the product if no mitigation is available, per CISA KEV required action.
- Verify no unauthorized admin accounts or configuration changes were made during any exposure window.
Detection
- Review Openfire web access logs for requests to setup environment paths containing traversal sequences (e.g., ../) or unexpected admin console URLs from unauthenticated sources.
- Alert on access to Admin Console pages from IPs outside expected administrative networks.
- Monitor for creation of new administrative accounts or unexpected configuration changes in Openfire.
- Correlate Openfire host activity with the public exploit references for post-exploitation behavior.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-32315 to the Known Exploited Vulnerabilities catalog on 24 August 2023 as "Ignite Realtime Openfire Path Traversal Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 14 September 2023.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/173607/Openfire-Authentication-Bypass-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/igniterealtime/Openfire/security/advisories/GHSA-gw42-f939-fhvm | ExploitMitigationPatchVendor Advisory |
| http://packetstormsecurity.com/files/173607/Openfire-Authentication-Bypass-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/igniterealtime/Openfire/security/advisories/GHSA-gw42-f939-fhvm | ExploitMitigationPatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-32315 | US Government Resource |
Track CVE-2023-32315 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-32315), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.