GHSA-h289-x5wc-xcv8

    Dashboard / Vulnerabilities / GHSA-h289-x5wc-xcv8

    GHSA-h289-x5wc-xcv8

    Published: 16 Feb 2022Last Modified: 20 May 2024

    Summary: Improper Validation of Certificate with Host Mismatch in mellium.im/xmpp/websocket

    Details: ### Impact If no TLS configuration is provided by the user, the websocket package constructs its own TLS configuration using recommended defaults. When looking up a WSS endpoint using the DNS TXT record method described in [XEP-0156: Discovering Alternative XMPP Connection Methods](https://xmpp.org/extensions/xep-0156.html) the ServerName field was incorrectly being set to the name of the server returned by the TXT record request, not the name of the initial server we were attempting to connect to. This means that any attacker that can spoof a DNS record (ie. in the absence of DNSSEC, DNS-over-TLS, DNS-over-HTTPS, or similar technologies) could redirect the user to a server of their choosing and as long as it had a valid TLS certificate for itself the connection would succeed, resulting in a MITM situation. ### Patches All users should upgrade to v0.21.1. ### Workarounds To work around the issue, manually specify a TLS configuration with the correct hostname. ### References - https://mellium.im/cve/cve-2022-24968/ - https://nvd.nist.gov/vuln/detail/CVE-2022-24968 ### For more information If you have any questions or comments about this advisory: * Reach out on XMPP to [[email protected]](xmpp:[email protected]?msg) * Email us at [[email protected]](mailto:[email protected])

    Affected packages

    Package

    Name: mellium.im/xmpp

    Purl: pkg:golang/mellium.im/xmpp

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0.18.0
    Fixed -0.21.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-h289-x5wc-xcv8 | CVE-DB