CVE-2022-24968

CVE-2022-24968

In Mellium mellium.im/xmpp through 0.21.0, an attacker capable of spoofing DNS TXT records can redirect a WebSocket connection request to a server under their control without causing TLS certificate verification to fail. This occurs because the wrong host name is selected during this verification.

Source: CVE-2022-24968

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다