Remote Spoofing Vulnerability in Ignite Realtime Smack XMPP API
CVE-2014-0364
Currently unrated
What is CVE-2014-0364?
The ParseRoster component in the Ignite Realtime Smack XMPP API prior to version 4.0.0-rc1 is susceptible to a remote spoofing vulnerability. This occurs due to the component's failure to validate the 'from' attribute in a roster-query IQ stanza. Consequently, attackers can exploit this oversight to send forged IQ responses, potentially compromising the integrity of user communications.
