Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qx52-4j2j-9hc7

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

plugins/mod_compression.lua in (1) Prosody before 0.9.4 and (2) Lightwitch Metronome through 3.4 negotiates stream compression while a session is unauthenticated, which allows remote attackers to cause a denial of service (resource consumption) via compressed XML elements in an XMPP stream, aka an "xmppbomb" attack.

plugins/mod_compression.lua in (1) Prosody before 0.9.4 and (2) Lightwitch Metronome through 3.4 negotiates stream compression while a session is unauthenticated, which allows remote attackers to cause a denial of service (resource consumption) via compressed XML elements in an XMPP stream, aka an "xmppbomb" attack.

EPSS

Процентиль: 84%
0.02179
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
почти 12 лет назад

plugins/mod_compression.lua in (1) Prosody before 0.9.4 and (2) Lightwitch Metronome through 3.4 negotiates stream compression while a session is unauthenticated, which allows remote attackers to cause a denial of service (resource consumption) via compressed XML elements in an XMPP stream, aka an "xmppbomb" attack.

nvd
почти 12 лет назад

plugins/mod_compression.lua in (1) Prosody before 0.9.4 and (2) Lightwitch Metronome through 3.4 negotiates stream compression while a session is unauthenticated, which allows remote attackers to cause a denial of service (resource consumption) via compressed XML elements in an XMPP stream, aka an "xmppbomb" attack.

debian
почти 12 лет назад

plugins/mod_compression.lua in (1) Prosody before 0.9.4 and (2) Lightw ...

EPSS

Процентиль: 84%
0.02179
Низкий

Дефекты

CWE-20