VYPR
Critical severity9.8NVD Advisory· Published Jan 28, 2020· Updated Jun 17, 2026

CVE-2020-8086

CVE-2020-8086

Description

The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP address passed to the is_admin() function. This grants remote entities admin-only functionality if their username matches the username of a local admin.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • cpe:2.3:a:prosody:mod_auth_ldap2:*:*:*:*:*:*:*:*
    Range: <=2020-01-27
  • cpe:2.3:a:prosody:mod_auth_ldap:*:*:*:*:*:*:*:*
    Range: <=2020-01-27
  • Debian/linux2 versions
    cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • Prosody/Prosodydescription
  • Prosody/Prosodyllm-fuzzy

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.