PT-2022-7426 · Gajim+3 · Gajim+3

Published

2022-09-22

·

Updated

2024-08-06

·

CVE-2022-39835

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Gajim versions 1.4.7 and earlier
Description The issue allows attackers to correct messages that were not sent by them via crafted XML stanzas. The attacker needs to be part of the group chat or single chat. This can potentially impact the integrity of the system.
Recommendations For Gajim versions 1.4.7 and earlier, update to version 1.5.0 to resolve the issue. As a temporary workaround, consider restricting access to group chats and single chats to minimize the risk of exploitation. Avoid using crafted XML stanzas in the affected API endpoints until the issue is resolved.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2655
BDU:2024-06030
CVE-2022-39835
OPENSUSE-SU-2024:12354-1

Affected Products

Alt Linux
Debian
Gajim
Red Os