PT-2018-10138 · Prosody+3 · Prosody+3

Princess Pepperoni

·

Published

2018-06-02

·

Updated

2021-03-15

·

CVE-2018-10847

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Prosody versions prior to 0.10.2 Prosody version 0.9.14
Description The issue allows for an authentication bypass. It occurs because Prosody does not verify that the virtual host associated with a user session remains the same across stream restarts. This means a user may authenticate to one XMPP host and then migrate their authenticated session to another XMPP host of the same Prosody instance.
Recommendations For versions prior to 0.10.2, update to version 0.10.2 or later. For version 0.9.14, consider upgrading to a newer version to mitigate the risk, as 0.9.14 is specifically mentioned as vulnerable.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2853
CVE-2018-10847
DSA-4216-1
OPENSUSE-SU-2018_1627-1
OPENSUSE-SU-2018_1632-1
USN-4834-1

Affected Products

Alt Linux
Prosody
Suse
Ubuntu