MEDIUM5.9
GHSA-w973-2qcc-p78x
User Impersonation in converse.js
Quick fix
GHSA-w973-2qcc-p78x — converse.js: upgrade to the fixed version with the command below.
npm install converse.js@1.0.7Details
Versions of `converse.js` prior to 1.0.7 for 1.x or 2.0.5 for 2.x are vulnerable to User Impersonation. The package provides an incorrect implementation of [XEP-0280: Message Carbons](https://xmpp.org/extensions/xep-0280.html) that allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks.
## Recommendation
If you're using `converse.js` 1.x, upgrade to 1.0.7 or later. If you're using `converse.js` 2.x, upgrade to 2.0.5 or later.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2017-5858[ADVISORY]
- https://github.com/jcbrand/converse.js/commit/42f249cabbbf5c026398e6d3b350f6f9536ea572[WEB]
- https://github.com/jcbrand/converse.js[PACKAGE]
- https://rt-solutions.de/en/2017/02/CVE-2017-5589_xmpp_carbons[WEB]
- https://rt-solutions.de/wp-content/uploads/2017/02/CVE-2017-5589_xmpp_carbons.pdf[WEB]
- https://snyk.io/vuln/SNYK-JS-CONVERSEJS-449664[WEB]
- https://www.npmjs.com/advisories/974[WEB]
- https://www.openwall.com/lists/oss-security/2017/02/09/29[WEB]
- http://openwall.com/lists/oss-security/2017/02/09/29[WEB]
- http://www.securityfocus.com/bid/96183[WEB]