Lucene search

K
nodejsGeorg LukasNODEJS:974
HistoryJun 17, 2019 - 2:55 p.m.

User Impersonation

2019-06-1714:55:31
Georg Lukas
www.npmjs.com
11

EPSS

0.004

Percentile

73.1%

Overview

Versions of converse.js prior to 1.0.7 for 1.x or 2.0.5 for 2.x are vulnerable to User Impersonation. The package provides an incorrect implementation of XEP-0280: Message Carbons that allows a remote attacker to impersonate any user, including contacts, in the vulnerable application’s display. This allows for various kinds of social engineering attacks.

Recommendation

If you’re using converse.js 1.x, upgrade to 1.0.7 or later.
If you’re using converse.js 2.x, upgrade to 2.0.5 or later.

References

EPSS

0.004

Percentile

73.1%