Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m658-p24x-p74r

Опубликовано: 12 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

Duplicate Advisory: TLS certificate validation error in mellium.im/xmpp

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-h289-x5wc-xcv8. This link is maintained to preserve external references.

Original Description

In Mellium mellium.im/xmpp through 0.21.0, an attacker capable of spoofing DNS TXT records can redirect a WebSocket connection request to a server under their control without causing TLS certificate verification to fail. This occurs because the wrong host name is selected during this verification.

Пакеты

Наименование

mellium.im/xmpp

go
Затронутые версииВерсия исправления

>= 0.18.0, < 0.21.1

0.21.1

5.9 Medium

CVSS3

Дефекты

CWE-295

5.9 Medium

CVSS3

Дефекты

CWE-295