CVE-2024-46957

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Sep 25, 2024
Updated: Sep 26, 2024
CWE ID 290

Summary

CVE-2024-46957 is a vulnerability affecting Mellium mellium.im/xmpp versions 0.0.1 to 0.21.4. An attacker could exploit this issue by crafting a response with a predictable ID, as the stanza type is not checked. This flaw enables response spoofing, allowing an attacker to impersonate another user in an XMPP (Extensible Messaging and Presence Protocol) communication. The vulnerability is resolved in version 0.22.0.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share