CVE-2018-10847
MEDIUMprosody < 0.10.2, < 0.9.14 - Authentication Bypass via Stream Restart
Title source: llmDescription
prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass. Prosody did not verify that the virtual host associated with a user session remained the same across stream restarts. A user may authenticate to XMPP host A and migrate their authenticated session to XMPP host B of the same Prosody instance.
References (5)
Core 5
Core References
Vendor Advisory x_refsource_confirm
https://issues.prosody.im/1147
Vendor Advisory x_refsource_confirm
https://blog.prosody.im/prosody-0-10-2-security-release/
Third Party Advisory vendor-advisory
x_refsource_debian
https://www.debian.org/security/2018/dsa-4216
Issue Tracking, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10847
Vendor Advisory x_refsource_confirm
https://prosody.im/security/advisory_20180531/
Scores
CVSS v3
4.2
EPSS
0.0166
EPSS Percentile
73.7%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Details
CWE
CWE-287
CWE-592
Status
published
Products (3)
prosody/prosody
0.10.0
prosody/prosody
0.10.1
prosody/prosody
< 0.9.14
Published
Jul 30, 2018
Tracked Since
Feb 18, 2026