Mellium mellium.im/xmpp 0.0.1 through 0.21.4 allows response spoofing if the implementation uses predictable IDs because the stanza type is not checked. This is fixed in 0.22.0.
History

Thu, 26 Sep 2024 16:15:00 +0000

Type Values Removed Values Added
Description Mellium mellium.im/xmpp 0.0.1 through 0.21.4 allows response spoofing because the stanza type is not checked. This is fixed in 0.22.0. Mellium mellium.im/xmpp 0.0.1 through 0.21.4 allows response spoofing if the implementation uses predictable IDs because the stanza type is not checked. This is fixed in 0.22.0.

Tue, 24 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Mellium
Mellium xmpp
Weaknesses CWE-290
CPEs cpe:2.3:a:mellium:xmpp:*:*:*:*:*:*:*:*
Vendors & Products Mellium
Mellium xmpp
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 24 Sep 2024 06:00:00 +0000

Type Values Removed Values Added
Description Mellium mellium.im/xmpp 0.0.1 through 0.21.4 allows response spoofing because the stanza type is not checked. This is fixed in 0.22.0.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-09-24T00:00:00

Updated: 2024-09-26T15:57:09.747345

Reserved: 2024-09-16T00:00:00

Link: CVE-2024-46957

cve-icon Vulnrichment

Updated: 2024-09-24T13:40:55.371Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-25T01:15:44.750

Modified: 2024-09-26T16:15:08.883

Link: CVE-2024-46957

cve-icon Redhat

No data.