The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP address passed to the is_admin() function. This grants remote entities admin-only functionality if their username matches the username of a local admin.
| Software | From | Fixed in |
|---|---|---|
| prosody / mod_auth_ldap2 | - | 2020-01-27.x |
| prosody / mod_auth_ldap | - | 2020-01-27.x |
| debian / debian_linux | 9.0 | 9.0.x |
| debian / debian_linux | 10.0 | 10.0.x |