An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for jappix 1.0.0 to 1.1.6.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "1.0.0"
},
{
"introduced": "0"
},
{
"last_affected": "1.0.1"
},
{
"introduced": "0"
},
{
"last_affected": "1.0.2"
},
{
"introduced": "0"
},
{
"last_affected": "1.0.3"
},
{
"introduced": "0"
},
{
"last_affected": "1.0.4"
},
{
"introduced": "0"
},
{
"last_affected": "1.0.5"
},
{
"introduced": "0"
},
{
"last_affected": "1.0.6"
},
{
"introduced": "0"
},
{
"last_affected": "1.0.7"
},
{
"introduced": "0"
},
{
"last_affected": "1.1.0"
},
{
"introduced": "0"
},
{
"last_affected": "1.1.1"
},
{
"introduced": "0"
},
{
"last_affected": "1.1.2"
},
{
"introduced": "0"
},
{
"last_affected": "1.1.3"
},
{
"introduced": "0"
},
{
"last_affected": "1.1.4"
},
{
"introduced": "0"
},
{
"last_affected": "1.1.5"
},
{
"introduced": "0"
},
{
"last_affected": "1.1.6"
}
]
}