QID 983700
QID 983700: Nodejs (npm) Security Update for converse.js (GHSA-w973-2qcc-p78x)
Versions of `converse.js` prior to 1.0.7 for 1.x or 2.0.5 for 2.x are vulnerable to User Impersonation. The package provides an incorrect implementation of [XEP-0280: Message Carbons](https://xmpp.org/extensions/xep-0280.html) that allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. ## Recommendation If you're using `converse.js` 1.x, upgrade to 1.0.7 or later. If you're using `converse.js` 2.x, upgrade to 2.0.5 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-w973-2qcc-p78x for updates pertaining to this vulnerability.
Vendor References
- GHSA-w973-2qcc-p78x -
github.com/advisories/GHSA-w973-2qcc-p78x
CVEs related to QID 983700
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-w973-2qcc-p78x | converse.js |
|