Prosody是一套使用Lua语言编写的Jabber/XMPP通信服务器软件。 Prosody 0.10.2之前版本和0.9.14之前版本中存在身份验证绕过漏洞,该漏洞源于在XMPP流重启期间Prosody没有验证与用户会话相关的虚拟主机是否保持一致。攻击者可利用该漏洞绕过安全策略,冒充用户名称。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2018-10898 | openstack-tripleo-heat-templates 安全漏洞 | |
| CVE-2018-10883 | Linux kernel 缓冲区错误漏洞 | |
| CVE-2018-10903 | python-cryptography 安全漏洞 | |
| CVE-2017-7482 | Linux kernel 缓冲区错误漏洞 | |
| CVE-2017-7518 | Linux kernel 安全漏洞 |
No comments yet