User Impersonation in converse.js
GHSA-w973-2qcc-p78x · CVE-2017-5858
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Versions of converse.js prior to 1.0.7 for 1.x or 2.0.5 for 2.x are vulnerable to User Impersonation. The package provides an incorrect implementation of XEP-0280: Message Carbons that allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks.
Recommendation
If you're using converse.js 1.x, upgrade to 1.0.7 or later.
If you're using converse.js 2.x, upgrade to 2.0.5 or later.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2017-5858
- WEB https://github.com/jcbrand/converse.js/commit/42f249cabbbf5c026398e6d3b350f6f9536ea572
- PACKAGE https://github.com/jcbrand/converse.js
- WEB https://rt-solutions.de/en/2017/02/CVE-2017-5589_xmpp_carbons
- WEB https://rt-solutions.de/wp-content/uploads/2017/02/CVE-2017-5589_xmpp_carbons.pdf
- WEB https://snyk.io/vuln/SNYK-JS-CONVERSEJS-449664
- WEB https://www.npmjs.com/advisories/974
- WEB https://www.openwall.com/lists/oss-security/2017/02/09/29
- WEB http://openwall.com/lists/oss-security/2017/02/09/29
- WEB http://www.securityfocus.com/bid/96183
Ready to move
Start Securing
Free, no credit card | First findings in minutes