Vulnerability detail
Enriched intelligence for a single CVE
High
CVE-2023-32315
PUBLISHEDOpenfire administration console authentication bypass
- Vendor
- igniterealtime
- Product
- Openfire
- Published
- May 26, 2023
- EPSS
- —
Description
Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based application, was found to be vulnerable to a path traversal attack via the setup environment. This permitted an unauthenticated user to use the unauthenticated Openfire Setup Environment in an already configured Openfire environment to access restricted pages in the Openfire Admin Console reserved for administrative users. This vulnerability affects all versions of Openfire that have been released since April 2015, starting with version 3.10.0. The problem has been patched in Openfire release 4.7.5 and 4.6.8, and further improvements will be included in the yet-to-be released first version on the 4.8 branch (which is expected to be version 4.8.0). Users are advised to upgrade. If an Openfire upgrade isn’t available for a specific release, or isn’t quickly actionable, users may see the linked github advisory (GHSA-gw42-f939-fhvm) for mitigation advice.
CVSS scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Exploitation status
Exploited in the wild
Recorded 2023-08-24 00:00:00 UTC · Source
SSVC decision points
- Exploitation
- active
- Automatable
- Yes
- Technical impact
- total
Known exploited vulnerability sources
Catalogues that list this CVE as a known exploited vulnerability.
| Source | Added |
|---|---|
| CISA | Aug 24, 2023 |
Scanner integrations
| Scanner | Reference | Detected |
|---|---|---|
| Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/openfire_auth_bypass_rce_cve_2023_32315.rb | Apr 28, 2025 |
| Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-32315.yaml | Apr 25, 2025 |
Potential proof of concepts
These PoCs are unverified and could contain malware. Use at your own risk.
metasploit · Created Unknown
Metasploit module for CVE-2023-32315
github · Created 2025-01-30 17:47:29 UTC · 0 stars
github · Created 2023-12-15 16:30:51 UTC · 8 stars
A PoC exploit for CVE-2023-32315 - Openfire Authentication Bypass
github · Created 2023-08-31 08:43:44 UTC · 3 stars
Tool for CVE-2023-32315 exploitation
github · Created 2023-07-07 07:48:24 UTC · 5 stars
CVE-2023-32315-Openfire-Bypass
github · Created 2023-07-02 20:38:14 UTC · 6 stars
Perform With Massive Openfire Unauthenticated Users
github · Created 2023-06-18 15:42:00 UTC · 51 stars
Openfire Console Authentication Bypass Vulnerability with RCE plugin
github · Created 2023-06-15 01:11:56 UTC · 2 stars
github · Created 2023-06-14 09:43:31 UTC · 134 stars
rce
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Added to KEVIntel
-
Detected by Nuclei
-
Detected by Metasploit