« Volver al listado

CVE-2014-2744

Estado: ModificadaAlta (7.8)—

plugins/mod_compression.lua in (1) Prosody before 0.9.4 and (2) Lightwitch Metronome through 3.4 negotiates stream compression while a session is unauthenticated, which allows remote attackers to cause a denial of service (resource consumption) via compressed XML elements in an XMPP stream, aka an "xmppbomb" attack.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2014-2744",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 6.9,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "security@debian.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-04-11T01:55:06.663",
  "references": [
    {
      "url": "http://blog.prosody.im/prosody-0-9-4-released/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@debian.org"
    },
    {
      "url": "http://code.lightwitch.org/metronome/rev/49f47277a411",
      "tags": [
        "Exploit",
        "Patch"
      ],
      "source": "security@debian.org"
    },
    {
      "url": "http://hg.prosody.im/0.9/rev/b3b1c9da38fb",
      "tags": [
        "Exploit",
        "Patch"
      ],
      "source": "security@debian.org"
    },
    {
      "url": "http://openwall.com/lists/oss-security/2014/04/07/7",
      "source": "security@debian.org"
    },
    {
      "url": "http://openwall.com/lists/oss-security/2014/04/09/1",
      "source": "security@debian.org"
    },
    {
      "url": "http://secunia.com/advisories/57710",
      "source": "security@debian.org"
    },
    {
      "url": "http://www.debian.org/security/2014/dsa-2895",
      "source": "security@debian.org"
    },
    {
      "url": "http://xmpp.org/resources/security-notices/uncontrolled-resource-consumption-with-highly-compressed-xmpp-stanzas/",
      "source": "security@debian.org"
    },
    {
      "url": "http://blog.prosody.im/prosody-0-9-4-released/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://code.lightwitch.org/metronome/rev/49f47277a411",
      "tags": [
        "Exploit",
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://hg.prosody.im/0.9/rev/b3b1c9da38fb",
      "tags": [
        "Exploit",
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://openwall.com/lists/oss-security/2014/04/07/7",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://openwall.com/lists/oss-security/2014/04/09/1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/57710",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.debian.org/security/2014/dsa-2895",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://xmpp.org/resources/security-notices/uncontrolled-resource-consumption-with-highly-compressed-xmpp-stanzas/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "plugins/mod_compression.lua in (1) Prosody before 0.9.4 and (2) Lightwitch Metronome through 3.4 negotiates stream compression while a session is unauthenticated, which allows remote attackers to cause a denial of service (resource consumption) via compressed XML elements in an XMPP stream, aka an \"xmppbomb\" attack."
    },
    {
      "lang": "es",
      "value": "plugins/mod_compression.lua en (1) Prosody anterior a 0.9.4 y  (2) Lightwitch Metronome hasta 3.4 negocia compresión de cadena mientras una sesión no está autenticada, lo que permite a atacantes remotos causar una denegación de servicio (consumo de recursos) a través de elementos XML comprimidos en una cadena XMPP, también conocido como un ataque \"xmppbomb\"."
    }
  ],
  "lastModified": "2026-06-17T00:07:05.797",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:lightwitch:metronome:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B9EEE202-6A1C-4F03-AB6B-0055E44AC19C",
              "versionEndIncluding": "3.4"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:prosody:prosody:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B3BC00F6-770F-4A75-956D-981D54265EA2",
              "versionEndIncluding": "0.9.3"
            },
            {
              "criteria": "cpe:2.3:a:prosody:prosody:0.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CAFD513E-D824-4A56-ACAC-C80D253D238E"
            },
            {
              "criteria": "cpe:2.3:a:prosody:prosody:0.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "66CADDFD-351C-4785-AA25-F15482563A0C"
            },
            {
              "criteria": "cpe:2.3:a:prosody:prosody:0.3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0EEB6D2F-91DF-452F-B93C-7E27B7F9AE3A"
            },
            {
              "criteria": "cpe:2.3:a:prosody:prosody:0.4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3C7C9A3A-25B6-4EFA-BFF0-B3EA4BE50D55"
            },
            {
              "criteria": "cpe:2.3:a:prosody:prosody:0.4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3849A36E-AE3C-4A64-A267-455E7DFA23FC"
            },
            {
              "criteria": "cpe:2.3:a:prosody:prosody:0.4.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BE46CE5D-C648-497C-9B9D-7053E57206ED"
            },
            {
              "criteria": "cpe:2.3:a:prosody:prosody:0.5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "72D503F4-503A-427E-8601-DC58ABF87556"
            },
            {
              "criteria": "cpe:2.3:a:prosody:prosody:0.5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "27B91228-E7DC-460A-9BB7-AEBB0DB6EF1F"
            },
            {
              "criteria": "cpe:2.3:a:prosody:prosody:0.5.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "641B719B-2739-4E1E-9BE1-B4082D8D85BD"
            },
            {
              "criteria": "cpe:2.3:a:prosody:prosody:0.6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "20E34C61-6749-4DDC-A9E0-50A96430CEA0"
            },
            {
              "criteria": "cpe:2.3:a:prosody:prosody:0.6.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "817100C0-4FCC-4DDE-8B4D-670854BEA3CA"
            },
            {
              "criteria": "cpe:2.3:a:prosody:prosody:0.6.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2445AF7B-643F-4436-BAB7-17027762A016"
            },
            {
              "criteria": "cpe:2.3:a:prosody:prosody:0.7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "14F2E897-2B3F-4435-8BAC-87CF347C9AB1"
            },
            {
              "criteria": "cpe:2.3:a:prosody:prosody:0.8.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9B894C4E-513C-4AF5-9500-D74F1D8DADA8"
            },
            {
              "criteria": "cpe:2.3:a:prosody:prosody:0.8.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B853EF1C-DC87-44FA-A4F0-AACE918F3F56"
            },
            {
              "criteria": "cpe:2.3:a:prosody:prosody:0.8.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "79A5214A-FEB7-44CA-9F56-BC23A39C7990"
            },
            {
              "criteria": "cpe:2.3:a:prosody:prosody:0.9.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "69BF8C97-A90B-4F1D-9300-F8BF411BDF69"
            },
            {
              "criteria": "cpe:2.3:a:prosody:prosody:0.9.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B70430C5-9AA2-46D5-B7DD-ED08CB980F47"
            },
            {
              "criteria": "cpe:2.3:a:prosody:prosody:0.9.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "19FFAE24-10BB-4F88-A0BF-105B4B6A702D"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@debian.org"
}