Описание
Security update for prosody
This update for prosody fixes the following issues:
This security issue was fixed:
- CVE-2018-10847: Prevent insufficient validation of client-provided parameters during XMPP stream restarts. Authenticated users may have overriden the realm associated with their session, potentially bypassing security policies and allowing impersonation (bsc#1094890).
Список пакетов
openSUSE Leap 42.3
prosody-0.9.13-2.6.1
Ссылки
- E-Mail link for openSUSE-SU-2018:1627-1
- SUSE Security Ratings
Описание
prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass. Prosody did not verify that the virtual host associated with a user session remained the same across stream restarts. A user may authenticate to XMPP host A and migrate their authenticated session to XMPP host B of the same Prosody instance.
Затронутые продукты
openSUSE Leap 42.3:prosody-0.9.13-2.6.1
Ссылки
- CVE-2018-10847
- SUSE Bug 1094890