DSA-4216-1 prosody -- prosodyID: oval:org.secpod.oval:def:603414 | Date: (C)2018-06-04 (M)2023-12-20 |
Class: PATCH | Family: unix |
It was discovered that Prosody, a lightweight Jabber/XMPP server, does not properly validate client-provided parameters during XMPP stream restarts, allowing authenticated users to override the realm associated with their session, potentially bypassing security policies and allowing impersonation. Details can be found in the upstream advisory at https://prosody.im/security/advisory_20180531/
Platform: |
Debian 8.x |
Debian 9.x |