Authentication Bypass by Spoofing
CVE-2024-46957
Summary
Mellium mellium.im/xmpp versions prior to 0.22.0 allow response spoofing if the implementation uses predictable IDs because the stanza type is not checked.
- LOW
- NETWORK
- HIGH
- UNCHANGED
- NONE
- NONE
- HIGH
- HIGH
CWE-290 - Authentication Bypass by Spoofing
This attack-focused weakness is caused by improperly implemented authentication schemes that are subject to spoofing attacks.
References
Advisory Timeline
- Published