VulnerabilityModified
CVE-2022-39835
The vulnerability allows attackers, via crafted XML stanzas, to correct messages that were not sent by them.
MEDIUM 5.3EPSS 0.50%
Does this matter?
Lower severity and a low EPSS score (0.50%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in Gajim through 1.4.7. The vulnerability allows attackers, via crafted XML stanzas, to correct messages that were not sent by them. The attacker needs to be part of the group chat or single chat. The fixed version is 1.5.0.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.50% probability · 41th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- gajim/gajim
- Source
- cve@mitre.org
References
- https://dev.gajim.org/gajim/gajim/-/blob/master/ChangeLogRelease Notes, Vendor Advisory
- https://dev.gajim.org/gajim/gajim/-/tagsVendor Advisory
- https://dev.gajim.org/gajim/gajim/-/blob/master/ChangeLogRelease Notes, Vendor Advisory
- https://dev.gajim.org/gajim/gajim/-/tagsVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.