CVE-2018-10847
Debian Security Advisory 4216-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass. Prosody did not verify that the virtual host associated with a user session remained the same across stream restarts. A user may authenticate to XMPP host A and migrate their authenticated session to XMPP host B of the same Prosody instance.
Prosody, en versiones anteriores a la 0.10.2 y 0.9.14, es vulnerable a una omisión de autenticación. Prosody no verificó que el host virtual asociado a una sesión de usuario se mantuviese igual durante los reinicios del flujo. Un usuario podría autenticarse en el host XMPP A y migrar su sesión autenticada al host XMPP B de la misma instancia Prosody.
It was discovered that Prosody, a lightweight Jabber/XMPP server, does not properly validate client-provided parameters during XMPP stream restarts, allowing authenticated users to override the realm associated with their session, potentially bypassing security policies and allowing impersonation.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-05-09 CVE Reserved
- 2018-06-04 CVE Published
- 2024-08-05 CVE Updated
- 2025-05-15 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-287: Improper Authentication
- CWE-592: DEPRECATED: Authentication Bypass Issues
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10847 | Issue Tracking |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://blog.prosody.im/prosody-0-10-2-security-release | 2019-10-09 | |
https://issues.prosody.im/1147 | 2019-10-09 | |
https://prosody.im/security/advisory_20180531 | 2019-10-09 | |
https://www.debian.org/security/2018/dsa-4216 | 2019-10-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Prosody Search vendor "Prosody" | Prosody Search vendor "Prosody" for product "Prosody" | < 0.9.14 Search vendor "Prosody" for product "Prosody" and version " < 0.9.14" | - |
Affected
| ||||||
Prosody Search vendor "Prosody" | Prosody Search vendor "Prosody" for product "Prosody" | 0.10.0 Search vendor "Prosody" for product "Prosody" and version "0.10.0" | - |
Affected
| ||||||
Prosody Search vendor "Prosody" | Prosody Search vendor "Prosody" for product "Prosody" | 0.10.1 Search vendor "Prosody" for product "Prosody" and version "0.10.1" | - |
Affected
|