Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xf9v-h9f2-2phh

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The generate_dialback function in the mod_dialback module in Prosody before 0.9.10 does not properly separate fields when generating dialback keys, which allows remote attackers to spoof XMPP network domains via a crafted stream id and domain name that is included in the target domain as a suffix.

The generate_dialback function in the mod_dialback module in Prosody before 0.9.10 does not properly separate fields when generating dialback keys, which allows remote attackers to spoof XMPP network domains via a crafted stream id and domain name that is included in the target domain as a suffix.

EPSS

Процентиль: 71%
0.00681
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 10 лет назад

The generate_dialback function in the mod_dialback module in Prosody before 0.9.10 does not properly separate fields when generating dialback keys, which allows remote attackers to spoof XMPP network domains via a crafted stream id and domain name that is included in the target domain as a suffix.

CVSS3: 5.3
nvd
около 10 лет назад

The generate_dialback function in the mod_dialback module in Prosody before 0.9.10 does not properly separate fields when generating dialback keys, which allows remote attackers to spoof XMPP network domains via a crafted stream id and domain name that is included in the target domain as a suffix.

CVSS3: 5.3
debian
около 10 лет назад

The generate_dialback function in the mod_dialback module in Prosody b ...

EPSS

Процентиль: 71%
0.00681
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-20