CVE-2018-10847

MEDIUM

prosody < 0.10.2, < 0.9.14 - Authentication Bypass via Stream Restart

Title source: llm
STIX 2.1

Description

prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass. Prosody did not verify that the virtual host associated with a user session remained the same across stream restarts. A user may authenticate to XMPP host A and migrate their authenticated session to XMPP host B of the same Prosody instance.

References (5)

Core 5
Core References
Vendor Advisory x_refsource_confirm
https://issues.prosody.im/1147
Vendor Advisory x_refsource_confirm
https://blog.prosody.im/prosody-0-10-2-security-release/
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2018/dsa-4216
Issue Tracking, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10847
Vendor Advisory x_refsource_confirm
https://prosody.im/security/advisory_20180531/

Scores

CVSS v3 4.2
EPSS 0.0166
EPSS Percentile 73.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Details

CWE
CWE-287 CWE-592
Status published
Products (3)
prosody/prosody 0.10.0
prosody/prosody 0.10.1
prosody/prosody < 0.9.14
Published Jul 30, 2018
Tracked Since Feb 18, 2026