CVE-2018-10847: High severity prosody vulnerability
prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass. Prosody did not verify that the virtual host associated with a user session remained the same across stream restarts. A user may authenticate to XMPP host A and migrate their authenticated session to XMPP host B of the same Prosody instance.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-10847?
CVE-2018-10847 is a vulnerability in Prosody, a XMPP server, that allows for authentication bypass.
What is the severity of CVE-2018-10847?
The severity of CVE-2018-10847 is high with a CVSS score of 8.8.
How does CVE-2018-10847 exploit work?
CVE-2018-10847 exploits the lack of verification of the virtual host associated with a user session and allows a user to migrate their authenticated session to a different XMPP host.
Which versions of Prosody are affected by CVE-2018-10847?
Versions before 0.10.2 and 0.9.14 of Prosody are affected by CVE-2018-10847.
How can I fix CVE-2018-10847?
To fix CVE-2018-10847, upgrade Prosody to version 0.10.2 or 0.9.14 or later.