Ignite Realtime Openfire through version 4.4.2 allows attackers to send arbitrary HTTP GET requests in FaviconServlet.java, resulting in server-side request forgery.
View the template here CVE-2019-18394.yaml
References:
https://github.com/igniterealtime/Openfire/pull/1497