CVE-2018-10847

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
30/07/2018
Last modified:
09/10/2019

Description

prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass. Prosody did not verify that the virtual host associated with a user session remained the same across stream restarts. A user may authenticate to XMPP host A and migrate their authenticated session to XMPP host B of the same Prosody instance.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:prosody:prosody:*:*:*:*:*:*:*:* 0.9.14 (excluding)
cpe:2.3:a:prosody:prosody:0.10.0:*:*:*:*:*:*:*
cpe:2.3:a:prosody:prosody:0.10.1:*:*:*:*:*:*:*