#1476 Reply on s2s using dialback multiplexing can be routed wrong

Reporter Zash
Owner Nobody
Created
Updated
Stars ★★ (2)
Tags
  • Priority-Medium
  • Type-Defect
  • Status-Accepted
  1. Zash on

    The session.send() function in mod_s2s uses the stream to/from for routing, but in case dialback multiplexing has been used this might not match the hosts in the to/from attrs on the stanza. So session.send(st.reply(stanza)) can be routed with the wrong hosts, however only hosts that has been authenticated via dialback can be used a source.

  2. Zash on

    Reported by dwd long ago

    Changes
    • tags Status-Accepted

New comment

Not published. Used for spam prevention and optional update notifications.