CVE-2020-8086: Critical severity Prosody Mod Auth Ldap vulnerability
The modauthldap and modauthldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP address passed to the isadmin() function. This grants remote entities admin-only functionality if their username matches the username of a local admin.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/prosody-modulesto a version that resolves this vulnerability.Fixed in 0.0~hg20190203.b54e98d5c4a1+dfsg-1+deb10u1Fixed in 0.0~hg20210130.dd3bfe8f182e+dfsg-2Fixed in 0.0~hg20230223.556bf57d6417+dfsg-1Fixed in 0.0~hg20231001.e5ad3f1f48bd+dfsg-1
Event History
Frequently Asked Questions
What is CVE-2020-8086?
CVE-2020-8086 is a vulnerability in the mod_auth_ldap and mod_auth_ldap2 Community Modules for Prosody.
How does CVE-2020-8086 affect Prosody?
CVE-2020-8086 allows remote entities to gain admin-only functionality in Prosody if their username matches the username of a local admin.
What is the severity of CVE-2020-8086?
CVE-2020-8086 has a severity rating of 9.8 (Critical).
Which software is affected by CVE-2020-8086?
The mod_auth_ldap and mod_auth_ldap2 Community Modules for Prosody, as well as Debian Linux versions 9.0 and 10.0, are affected by CVE-2020-8086.
How can I fix CVE-2020-8086?
To fix CVE-2020-8086, upgrade to the latest version of the affected software or apply the provided security patches.