ejabberd

ejabberd 26.09

We are pleased to announce the publication of ejabberd 26.09, which includes several security fixes, some improvements and other minor bugfixes. It is strongly encouraged that you update ejabberd as soon as possible.

Jérôme Sautret
· 5 min read
Send by email

Contents:

Security fixes

This release contains fixes for those security issues:

  • Unauthenticated Remote Code Execution on ejabberd (reported by Gia Bui) when:
    • ejabberd versions is at least 25.10
    • BOSH is enabled on any port
    • S2S is enabled
    • mod_adhoc_api is loaded
    • outbound connectivity from ejabberd on ports epmd (default 4369), s2s (default 5269) and Erlang distribution port (dynamically assigned, typically in the range 49152-65535 unless FIREWALL_WINDOW is set in ejabberdctl.cfg).
  • DoS attack on 16.12+ versions if BOSH is enabled on any port.
  • Cross-Tenant MUC, Roster and Shared-Roster unauthorized access (reported by Hoang Gia).

Fixed the ordering of some XML child elements

There was a reference-ordering problem in the fast_xml generator, it generated XML encoders that could reorder child elements in a different order from the one declared in the codec specification. From now, the order is the one declared in the codec specification. See details in https://github.com/processone/fast_xml/pull/53

Additionally there was an incorrect sasl2_continue declaration order in the xmpp erlang library: it declared "additional-data, text, tasks". Now it follows the ordering defined in XEP-0388 schema: "additional-data, tasks, text". See details in https://github.com/processone/xmpp/pull/112

New option for CAPTCHA POW

New toplevel option captcha_pow adds a SHA-256 hashcash challenge as described in XEP-0158 in the CAPTCHA form, alongside the image challenge or on its own.

Unlike the image challenge, this does not require setting the option captcha_cmd.

This option is used only by mod_register when registering a new account using In-Band Registration, not in MUC rooms or in mod_register_web. It is disabled by default.

Improved support for vhost-admins

It is well known how to grant administrative privileges to an account: by adding that account to an acl called admin:

acl:
  admin:
    user: admin1@localhost

The default ejabberd configuration uses this admin ACL in many places:

Consequently, that admin account can administer all of ejabberd: all the global features, all the modules, in all the vhosts... For now let's call it a "global admin".

If you have several vhosts, you can allow specific accounts to administer only specific vhosts. Let's call them "vhost-admins". In this example admin1@localhost can execute commands on all vhosts. Additionally, localhost has a vhost-admin, second has two vhosts-admins, and third has a vhost-admin:

hosts:
 - localhost
 - second
 - third

acl:
  admin:
    user: admin1@localhost

append_host_config:
  localhost:
    acl:
      aclhostadmin:
        - user: hostadmin@localhost
  second:
    acl:
      aclhostadmin:
        - user: hostadmin@second
        - user: hostadmin@third
  third:
    acl:
      aclhostadmin:
        - user: hostadmin@second

api_permissions:
  "vhost http access":
    from: mod_http_api
    who:
      access:
        allow:
          - acl: admin
        allow:
          - acl: aclhostadmin
    what: "*"

Example call of a vhost command by a vhost-admin:

$ curl --basic --user hostadmin@third:somepass -k \
  'https://localhost:5443/api/status_num_host?host=second&status=dnd'
7

If a vhost-admin tries to execute an API command directed to a vhost he does not administer, or a global command (that has no host argument, and affects all ejabberd), they are rejected:

$ curl --basic --user hostadmin@third:somepass -k \
  'https://localhost:5443/api/status_num_host?host=third&status=dnd'
{"code":32,
 "message":"AccessRules: Account does not have the right to perform the operation.",
 "status":"error"}

$ curl --basic --user hostadmin@third:somepass -k \
  'https://localhost:5443/api/stats?name=registeredusers'
{"code":32,
 "message":"AccessRules: Account does not have the right to perform the operation.",
 "status":"error"}

ChangeLog

Security fixes

  • Unauthenticated Remote Code Execution on ejabberd
  • DoS attack on BOSH
  • Cross-Tenant MUC, Roster and Shared-Roster unauthorized access

Core

  • Add force value to auth_external_user_exists_check option
  • Add XEP-0158 SHA-256 hashcash CAPTCHA challenge (#4594)
  • Add gen_mod:get_module_proc_check()
  • Fix to preserve reference order in XML, done in fast_xml and xmpp (#4606)
  • Get rid of couple *_to_atom
  • Make ejabberd_cluster:*call operate only on known nodes
  • More fixes for arguments in commands for vhost-admin
  • Optimize acl:load_tab()
  • ejabberd_systemd: Prefer matching over length/1
  • Updated Portuguese-Brazil and Chinese-Simplified translations

Modules

  • mod_auth_fast: Make sure that fast tokens can be used only with method that they were created for
  • mod_invites: don't apply overuse limit if max_invites is infinity (#4615)
  • mod_invites: don't crash in get_invite_by_invitee_t if reset_token present (#4620)
  • mod_invites: now that Conversations is for free we remove Yaxim (#4621)
  • mod_mix: Make access_create rule be applied when creating channel
  • mod_mqtt: Add lower limits for pre-auth packets
  • mod_muc_room: Fix handling of hats request with missing xdata
  • mod_muc_rtbl: Accept also plain account and domain JIDs
  • mod_muc_rtbl: Fix handling of remote ban servers (#4622)
  • mod_register: After changing password disallow password change on currently authenticated sessions

SQL

  • Add db_serialize to mod_privacy and mod_pubsub
  • Add rename_column op to ejabbrd_sql_schema update routines
  • Make rename_column compatible with older mysql versions
  • ejabberd_sql_schema: Escape all column/table names
  • Update mod_roster serializer with info about approved field

Administration

  • Allow vhost-admin to execute MUC commands for his vhost (#4603)
  • Fix method to check vhost-admin permission in Host API (#4619)
  • WebAdmin: Fix shared roster page when visited by vhost-admin
  • WebAdmin: For vhost-admins, hide useless link to node page
  • WebAdmin: Show proper domain in URLs, not the first configured vhost

Installers and Container

  • make-binaries: Bump Elixir to 1.19.6
  • make-binaries: Bump Erlang/OTP version to 28.5.0.7
  • make-binaries: Bump Expat version to 2.8.5
  • make-binaries: Bump JPEG version to 10
  • make-binaries: Bump OpenSSL 3.6.4
  • make-binaries: Bump PNG version to 1.6.58
  • make-binaries: Bump SQLite version to 3530400
  • make-binaries: Bump WebP version to 1.6.0
  • Dockerfile: Workaround to get image with amd64 (#4598)

Full Changelog

https://github.com/processone/ejabberd/compare/26.07...26.09

Acknowledgments

We would like to thank for the security reports provided by:

the contributions to the source code by:

and the translation by:

  • Daltux for updating the Portuguese (Brazil) translation
  • Sketch6580 for updating the Chinese (Simplified) translation

And also to all the people contributing in the ejabberd chatroom, issue tracker...

Improvements in ejabberd Business Edition

Customers of the ejabberd Business Edition, in addition to all those bugfixes, also get the following changes:

  • Improve p1db serialization
  • Fix SQLite backend for push
  • Recognize gateway_sandbox option inside mod_applepush service (to change sandbox connection endpoint)

Changes in SQL schema

MySQL

When using multihost schema:

ALTER TABLE push_gate CHANGE COLUMN user username text NOT NULL;
CREATE INDEX i_push_gate_username_server_host USING BTREE ON `push_gate`(username(191), server_host(191));

Otherwise:

ALTER TABLE push_gate RENAME COLUMN user TO username;
CREATE INDEX i_push_gate_username USING BTREE ON `push_gate`(username(191));

PgSql

When using multihost schema:

ALTER TABLE push_gate RENAME COLUMN "user" TO "username";
CREATE INDEX i_push_gate_token_server_host ON "push_gate" USING btree ("username", "server_host");

Otherwise:

ALTER TABLE push_gate RENAME COLUMN "user" TO "username";
CREATE INDEX i_push_gate_token ON "push_gate" USING btree ("username");

ejabberd 26.09 download & feedback

As usual, the release is tagged in the Git source code repository on GitHub.

The source package and installers are available in ejabberd Downloads page. To check the *.asc signature files, see How to verify ProcessOne downloads integrity.

For convenience, there are alternative download locations like the ejabberd DEB/RPM Packages Repository and the GitHub Release / Tags.

The ecs container image is available in docker.io/ejabberd/ecs and ghcr.io/processone/ecs. The alternative ejabberd container image is available in ghcr.io/processone/ejabberd.

If you consider that you've found a bug, please search or fill a bug report on GitHub Issues.