prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass. Prosody did not verify that the virtual host associated with a user session remained the same across stream restarts. A user may authenticate to XMPP host A and migrate their authenticated session to XMPP host B of the same Prosody instance.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2018-07-30T16:00:00
Updated: 2024-08-05T07:46:47.419Z
Reserved: 2018-05-09T00:00:00
Link: CVE-2018-10847
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-07-30T17:29:00.147
Modified: 2024-11-21T03:42:08.087
Link: CVE-2018-10847
Redhat
No data.