Details
-
Type:
Bug
-
Status: Closed (View workflow)
-
Priority:
Critical
-
Resolution: Fixed
-
Affects versions: 3.4.1
-
Fix versions: 4.0.0
-
Components: Core
-
Labels:None
Description
Reported by Thijs Alkemade: parseRoster @ PacketParserUtils.java:415 does not check the sender of the roster at all but also does not care whether or not a roster query was pending. This means that anybody can add new roster contacts, with a chosen alias and chosen groups. I've verified that this works in Yaxim.