Insufficient Verification of Data Authenticity Affecting org.igniterealtime.smack:smack package, versions [0,]
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JAVA-ORGIGNITEREALTIMESMACK-31184
- published 10 Feb 2015
- disclosed 30 Apr 2014
- credit Unknown
Introduced: 30 Apr 2014
CVE-2014-0364 Open this link in a new tabHow to fix?
There is no fixed version for org.igniterealtime.smack:smack
.
Overview
org.igniterealtime.smack:smack is an Open Source XMPP (Jabber) client library for instant messaging and presence. This library provides the client side functionality as specified in the core XMPP specifications as related to the client side of said specifications.
Affected versions of this package are vulnerable to Insufficient Verification of Data Authenticity. The ParseRoster component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify the from attribute of a roster-query IQ stanza, which allows remote attackers to spoof IQ responses via a crafted attribute.