Insufficient Verification of Data Authenticity Affecting org.igniterealtime.smack:smack package, versions [0,]


0.0
medium

Snyk CVSS

    Attack Complexity Low
NVD  medium

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-JAVA-ORGIGNITEREALTIMESMACK-31184
  • published 10 Feb 2015
  • disclosed 30 Apr 2014
  • credit Unknown

How to fix?

There is no fixed version for org.igniterealtime.smack:smack.

Overview

org.igniterealtime.smack:smack is an Open Source XMPP (Jabber) client library for instant messaging and presence. This library provides the client side functionality as specified in the core XMPP specifications as related to the client side of said specifications.

Affected versions of this package are vulnerable to Insufficient Verification of Data Authenticity. The ParseRoster component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify the from attribute of a roster-query IQ stanza, which allows remote attackers to spoof IQ responses via a crafted attribute.

References