Ejabberd DoS via malformed stanza
Moderate severity
GitHub Reviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Jan 19, 2024
Package
Affected versions
<= 2.1.8
>= 3.0.0-alpha-1, <= 3.0.0-alpha-3
Patched versions
2.1.9
3.0.0-alpha-4
Description
Published by the National Vulnerability Database
Feb 18, 2012
Published to the GitHub Advisory Database
May 17, 2022
Reviewed
Jan 19, 2024
Last updated
Jan 19, 2024
The
mod_pubsub
module (mod_pubsub.erl) in ejabberd 2.1.8 and 3.0.0-alpha-3 allows remote authenticated users to cause a denial of service (infinite loop) via a stanza with a publish tag that lacks a node attribute.References