Junglewise Threat Intelligence

CVE-2018-6591: Converse.js sensitive information exposure in bookmarks

CVE-2018-6591 · Severity: low · CVSS 3 · Published 2022-05-14

Vendors: Packagist.

Executive brief

Converse.js is a JavaScript-based XMPP chat client library. The vulnerability allows chatroom bookmarks and other private data to be exposed to remote attackers because the software does not reliably prevent unintended publication of sensitive information through its data sharing mechanisms. This could lead to confidential chat information being disclosed to unauthorized parties.

Technical details

The vulnerability is an information disclosure issue (CWE-200) affecting Converse.js and Inverse.js through version 3.3. The root cause is insufficient validation of XMPP Publish-Subscribe (PEP) publish options: the application does not adequately verify whether safe publication of private data was configured before transmitting data to XMPP servers. Specifically, chatroom bookmarks and similar private data could be published without proper access controls if publish-options are not advertised. The vulnerability requires network access to an XMPP server and affects all users of affected versions. The fix (version 3.3.3 and later) adds validation to ensure PEP bookmarks are only allowed when publish-options capability is advertised by the server.

Affected products

  • Converse.js Project Converse.js through 3.3, prior to 3.3.3
  • Converse.js Project Inverse.js through 3.3, prior to 3.3.3

Timeline

  • 2018-02-19: disclosed: NVD publication date
  • 2018-02-08: patched: Fix commit (version 3.3.3)
  • 2022-05-14: advisory: GHSA advisory published

References