Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-10847

Опубликовано: 30 июл. 2018
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 6.5
CVSS3: 4.2

Описание

prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass. Prosody did not verify that the virtual host associated with a user session remained the same across stream restarts. A user may authenticate to XMPP host A and migrate their authenticated session to XMPP host B of the same Prosody instance.

РелизСтатусПримечание
artful

released

0.9.12-2+deb9u2build0.17.10.1
bionic

ignored

end of standard support, was needed
cosmic

not-affected

devel

not-affected

disco

not-affected

eoan

not-affected

esm-apps/bionic

released

0.10.0-1ubuntu0.1~esm1
esm-apps/focal

not-affected

esm-apps/jammy

not-affected

esm-apps/noble

not-affected

Показывать по

EPSS

Процентиль: 79%
0.01304
Низкий

6.5 Medium

CVSS2

4.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.2
nvd
больше 7 лет назад

prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass. Prosody did not verify that the virtual host associated with a user session remained the same across stream restarts. A user may authenticate to XMPP host A and migrate their authenticated session to XMPP host B of the same Prosody instance.

CVSS3: 4.2
debian
больше 7 лет назад

prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authenticat ...

suse-cvrf
больше 7 лет назад

Security update for prosody

suse-cvrf
больше 7 лет назад

Security update for prosody

CVSS3: 8.8
github
больше 3 лет назад

prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass. Prosody did not verify that the virtual host associated with a user session remained the same across stream restarts. A user may authenticate to XMPP host A and migrate their authenticated session to XMPP host B of the same Prosody instance.

EPSS

Процентиль: 79%
0.01304
Низкий

6.5 Medium

CVSS2

4.2 Medium

CVSS3