PT-2022-4676 · Prosody+2 · Prosody+2

Matthew Wild

·

Published

2022-01-14

·

Updated

2024-12-08

·

CVE-2022-0217

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Prosody (affected versions not specified)
Description The issue is related to the implementation of the WebSocket server module for Jabber/XMPP in Prosody, which is associated with incorrect restriction of XML links to external objects. This can lead to a denial of service when exploited by a remote attacker. The problem arises from an internal Prosody library that loads XML based on libexpat, failing to properly restrict the allowed XML features in parsed XML data. As a result, it may allow the expansion of recursive entity references from DTDs and, depending on the libexpat version, potentially enable injections using XML External Entity References.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XML Entity Expansion

XXE

RCE

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1065
ALT-PU-2022-1150
ALT-PU-2022-1162
ALT-PU-2024-16554
BDU:2022-05563
CVE-2022-0217
DSA-5047-1
DSA-5047-2
OPENSUSE-SU-2022:0012-1
OPENSUSE-SU-2024:11736-1

Affected Products

Alt Linux
Prosody
Libexpat