Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w973-2qcc-p78x

Опубликовано: 11 сент. 2020
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

User Impersonation in converse.js

Versions of converse.js prior to 1.0.7 for 1.x or 2.0.5 for 2.x are vulnerable to User Impersonation. The package provides an incorrect implementation of XEP-0280: Message Carbons that allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks.

Recommendation

If you're using converse.js 1.x, upgrade to 1.0.7 or later. If you're using converse.js 2.x, upgrade to 2.0.5 or later.

Пакеты

Наименование

converse.js

npm
Затронутые версииВерсия исправления

< 1.0.7

1.0.7

Наименование

converse.js

npm
Затронутые версииВерсия исправления

>= 2.0.0, < 2.0.5

2.0.5

EPSS

Процентиль: 48%
0.00253
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-20
CWE-346

Связанные уязвимости

CVSS3: 5.9
nvd
почти 9 лет назад

An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for Converse.js (0.8.0 - 1.0.6, 2.0.0 - 2.0.4).

EPSS

Процентиль: 48%
0.00253
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-20
CWE-346