Описание
Duplicate Advisory: TLS certificate validation error in mellium.im/xmpp
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-h289-x5wc-xcv8. This link is maintained to preserve external references.
Original Description
In Mellium mellium.im/xmpp through 0.21.0, an attacker capable of spoofing DNS TXT records can redirect a WebSocket connection request to a server under their control without causing TLS certificate verification to fail. This occurs because the wrong host name is selected during this verification.
Пакеты
Наименование
mellium.im/xmpp
go
Затронутые версииВерсия исправления
>= 0.18.0, < 0.21.1
0.21.1
5.9 Medium
CVSS3
Дефекты
CWE-295
5.9 Medium
CVSS3
Дефекты
CWE-295