{"id":"GO-2021-0321","details":"An attacker capable of spoofing DNS TXT records can redirect a\nWebSocket connection request to a server under their control without\ncausing TLS certificate verification to fail. This occurs because\nthe wrong host name is selected during this verification.\n","modified":"2022-08-29T16:50:59Z","published":"2022-03-15T19:38:30Z","withdrawn":"2024-05-15T05:37:11.009858Z","references":[{"type":"FIX","url":"https://github.com/mellium/xmpp/pull/260"},{"type":"FIX","url":"https://github.com/mellium/xmpp/commit/0d92aa486da69b71f2f4a30e62aa722c711b98ac"},{"type":"WEB","url":"https://mellium.im/cve/cve-2022-24968/"}],"affected":[{"package":{"name":"mellium.im/xmpp","ecosystem":"Go","purl":"pkg:golang/mellium.im/xmpp"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.18.0"},{"fixed":"0.21.1"}]}],"ecosystem_specific":{"imports":[{"path":"mellium.im/xmpp/websocket","symbols":["Dialer.config"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2021-0321.json","url":"https://pkg.go.dev/vuln/GO-2021-0321"}}],"schema_version":"1.7.3"}