PT-2022-7426 · Gajim+3 · Gajim+3
Published
2022-09-22
·
Updated
2024-08-06
·
CVE-2022-39835
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Gajim versions 1.4.7 and earlier
Description
The issue allows attackers to correct messages that were not sent by them via crafted XML stanzas. The attacker needs to be part of the group chat or single chat. This can potentially impact the integrity of the system.
Recommendations
For Gajim versions 1.4.7 and earlier, update to version 1.5.0 to resolve the issue. As a temporary workaround, consider restricting access to group chats and single chats to minimize the risk of exploitation. Avoid using crafted XML stanzas in the affected API endpoints until the issue is resolved.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Debian
Gajim
Red Os