Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q477-8j82-fjq4

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd party's roster as another user, which will also garner associated privileges, via crafted XMPP packets.

MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd party's roster as another user, which will also garner associated privileges, via crafted XMPP packets.

EPSS

Процентиль: 91%
0.04512
Низкий

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 7.4
ubuntu
больше 6 лет назад

MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd party's roster as another user, which will also garner associated privileges, via crafted XMPP packets.

CVSS3: 7.4
nvd
больше 6 лет назад

MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd party's roster as another user, which will also garner associated privileges, via crafted XMPP packets.

CVSS3: 7.4
debian
больше 6 лет назад

MCabber before 1.0.4 is vulnerable to roster push attacks, which allow ...

suse-cvrf
больше 9 лет назад

Security update for python3-sleekxmpp

EPSS

Процентиль: 91%
0.04512
Низкий

Дефекты

CWE-269