Bug ID 1124322
Summary VUL-1: CVE-2019-1000021: python-slixmpp: incorrect Access Control vulnerability in XEP-0223 plugin (Persistent Storage of Private Data via PubSub)
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.0
Hardware Other
URL https://smash.suse.de/issue/224195/
OS Other
Status NEW
Severity Minor
Priority P5 - None
Component Security
Assignee sor.alexei@meowr.ru
Reporter rfrohl@suse.com
QA Contact security-team@suse.de
CC mvetter@suse.com
Found By Security Response Team
Blocker ---

CVE-2019-1000021

slixmpp version before commit 7cd73b594e8122dddf847953fcfc85ab4d316416 contains
an incorrect Access Control vulnerability in XEP-0223 plugin (Persistent
Storage
of Private Data via PubSub) options profile, used for the configuration of
default access model that can result in all of the contacts of the victim can
see private data having been published to a PEP node. This attack appears to be
exploitable if the user of this library publishes any private data on PEP, the
node isn't configured to be private. This vulnerability appears to have been
fixed in commit 7cd73b594e8122dddf847953fcfc85ab4d316416 which is included in
slixmpp 1.4.2.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-1000021
https://xmpp.org/extensions/xep-0223.html#howitworks
https://lab.louiz.org/poezio/slixmpp/commit/7cd73b594e8122dddf847953fcfc85ab4d316416


You are receiving this mail because: