XEP-Remarks/XEP-0313: Message Archive Management
Revision as of 17:35, 31 January 2021 by Zash (talk | contribs) (→Client-side Processing: Add CVE-2020-26547 in Monal)
This is a page for information about XEP-Remarks/XEP-0313: Message Archive Management, including errata, comments, questions, and implementation experience. |
Client-side Processing
Forwarded messages MUST NOT be accepted from JIDs other than the user's bare account JID, or else:
- CVE-2019-16235+ Multiple Vulnerabilities found in Dino
- CVE-2017-5589+ Multiple XMPP Clients User Impersonation Vulnerability (similar, but not identical issue)
- CVE-2020-26547 Missing verification of origin of MAM results in Monal