PT-2020-2096 · Prosody · Prosody
Matthew Wild
·
Published
2020-01-28
·
Updated
2020-02-04
·
CVE-2020-8086
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Prosody mod auth ldap and mod auth ldap2 Community Modules versions prior to 2020-01-27
Description
The issue is related to the incomplete verification of the XMPP address passed to the
is admin() function in the mod auth ldap and mod auth ldap2 Community Modules for Prosody. This can allow a remote entity to gain admin-only functionality if their username matches that of a local admin, potentially leading to unauthorized access to confidential data, disruption of data integrity, and denial of service.Recommendations
For Prosody mod auth ldap and mod auth ldap2 Community Modules versions prior to 2020-01-27, update to a version released after 2020-01-27 to ensure proper verification of XMPP addresses and prevent unauthorized access. As a temporary workaround, consider restricting access to admin-only functionality until the update can be applied.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Prosody