Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q477-8j82-fjq4

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd party's roster as another user, which will also garner associated privileges, via crafted XMPP packets.

MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd party's roster as another user, which will also garner associated privileges, via crafted XMPP packets.

EPSS

Процентиль: 89%
0.04514
Низкий

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 7.4
ubuntu
около 6 лет назад

MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd party's roster as another user, which will also garner associated privileges, via crafted XMPP packets.

CVSS3: 7.4
nvd
около 6 лет назад

MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd party's roster as another user, which will also garner associated privileges, via crafted XMPP packets.

CVSS3: 7.4
debian
около 6 лет назад

MCabber before 1.0.4 is vulnerable to roster push attacks, which allow ...

suse-cvrf
около 9 лет назад

Security update for python3-sleekxmpp

EPSS

Процентиль: 89%
0.04514
Низкий

Дефекты

CWE-269