PT-2020-2096 · Prosody · Prosody

Matthew Wild

·

Published

2020-01-28

·

Updated

2020-02-04

·

CVE-2020-8086

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Prosody mod auth ldap and mod auth ldap2 Community Modules versions prior to 2020-01-27
Description The issue is related to the incomplete verification of the XMPP address passed to the is admin() function in the mod auth ldap and mod auth ldap2 Community Modules for Prosody. This can allow a remote entity to gain admin-only functionality if their username matches that of a local admin, potentially leading to unauthorized access to confidential data, disruption of data integrity, and denial of service.
Recommendations For Prosody mod auth ldap and mod auth ldap2 Community Modules versions prior to 2020-01-27, update to a version released after 2020-01-27 to ensure proper verification of XMPP addresses and prevent unauthorized access. As a temporary workaround, consider restricting access to admin-only functionality until the update can be applied.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-01956
CVE-2020-8086
DSA-4612-1

Affected Products

Prosody