CVE-2023-32315: Openfire Administration Console authentication bypass

In my case (Ubuntu server) it installed a crypto-miner malware “kdevtmpfsi” and “kinsing” which used entire CPU.

Lots of new users in Openfire and in Security Audit Log many times this:

openfiresupport uploaded plugin plugin.jar
openfiresupport deleted plugin product
OpenfireSupport Successful admin console login attempt

I had to:

  1. stop the openfire service, delete that plugin from /var/lib/openfire/plugins
  2. delete all new users
  3. upgrade to openfire 4.7.5

also get rid of that malware:

  1. killall kdevtmpfsi*; killall kinsing*;
  2. delete files from /tmp directory

It seems clean since then.

1 Like