Your submission was sent successfully! Close

CVE-2018-10847

Published: 30 July 2018

prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass. Prosody did not verify that the virtual host associated with a user session remained the same across stream restarts. A user may authenticate to XMPP host A and migrate their authenticated session to XMPP host B of the same Prosody instance.

Priority

Low

CVSS 3 base score: 8.8

Status

Package Release Status
prosody
Launchpad, Ubuntu, Debian
artful
Released (0.9.12-2+deb9u2build0.17.10.1)
bionic Needed

cosmic Not vulnerable

disco Not vulnerable

eoan Not vulnerable

focal Not vulnerable

groovy Not vulnerable

hirsute Not vulnerable

impish Not vulnerable

jammy Not vulnerable

precise Does not exist

trusty Does not exist
(trusty was needed)
upstream Needs triage

xenial Ignored
(end of standard support, was needed)