Insufficient Verification of Data Authenticity Affecting org.igniterealtime.smack:smack Open this link in a new tab package, versions [0,]
Attack Complexity
Low
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications-
snyk-id
SNYK-JAVA-ORGIGNITEREALTIMESMACK-31184
-
published
10 Feb 2015
-
disclosed
30 Apr 2014
-
credit
Unknown
Introduced: 30 Apr 2014
CVE-2014-0364 Open this link in a new tabHow to fix?
There is no fixed version for org.igniterealtime.smack:smack
.
Overview
org.igniterealtime.smack:smack is an Open Source XMPP (Jabber) client library for instant messaging and presence. This library provides the client side functionality as specified in the core XMPP specifications as related to the client side of said specifications.
Affected versions of this package are vulnerable to Insufficient Verification of Data Authenticity. The ParseRoster component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify the from attribute of a roster-query IQ stanza, which allows remote attackers to spoof IQ responses via a crafted attribute.