Release notes copied from the original ejabberd 26.09 announcement post:
We are pleased to announce the publication of ejabberd 26.09, which includes several security fixes, some improvements and other minor bugfixes. It is strongly encouraged that you update ejabberd as soon as possible.
Contents:
- Security fixes
- Fixed the ordering of some XML child elements
- New option for CAPTCHA POW
- ChangeLog
- Acknowledgments
- Improvements in ejabberd Business Edition
- ejabberd 26.09 download & feedback
Security fixes
This release contains fixes for those security issues:
- Unauthenticated Remote Code Execution on ejabberd (reported by Gia Bui) when:
- ejabberd versions is at least 25.10
- BOSH is enabled on any port
- S2S is enabled
- mod_adhoc_api is loaded
- outbound connectivity from ejabberd on ports epmd (default 4369), s2s (default 5269) and Erlang distribution port (dynamically assigned, typically in the range 49152-65535 unless FIREWALL_WINDOW is set in ejabberdctl.cfg).
- DoS attack on 16.12+ versions if BOSH is enabled on any port.
- Cross-Tenant MUC, Roster and Shared-Roster unauthorized access (reported by Hoang Gia).
Fixed the ordering of some XML child elements
There was a reference-ordering problem in the fast_xml generator, it generated XML encoders that could reorder child elements in a different order from the one declared in the codec specification. From now, the order is the one declared in the codec specification. See details in processone/fast_xml#53
Additionally there was an incorrect sasl2_continue declaration order in the xmpp erlang library: it declared "additional-data, text, tasks". Now it follows the ordering defined in XEP-0388 schema: "additional-data, tasks, text". See details in processone/xmpp#112
New option for CAPTCHA POW
New toplevel option captcha_pow adds a SHA-256 hashcash challenge as described in XEP-0158 in the CAPTCHA form, alongside the image challenge or on its own.
Unlike the image challenge, this does not require setting the option captcha_cmd.
This option is used only by mod_register when registering a new account using In-Band Registration, not in MUC rooms or in mod_register_web. It is disabled by default.
Improved support for vhost-admins
It is well known how to grant administrative privileges to an account: by adding that account to an acl called admin:
acl:
admin:
user: admin1@localhostThe default ejabberd configuration uses this admin ACL in many places:
- the
announceaccess rule used bymod_announce - the
configureaccess rule used bymod_configureand WebAdmin - several
api_permissionsentries used to execute API commands in WebAdmin,mod_adhoc_api,mod_http_api, ... - some
shaper_rules - many options modules, for example
access_adminoption inmod_muc
Consequently, that admin account can administer all of ejabberd: all the global features, all the modules, in all the vhosts... For now let's call it a "global admin".
If you have several vhosts, you can allow specific accounts to administer only specific vhosts. Let's call them "vhost-admins". In this example admin1@localhost can execute commands on all vhosts. Additionally, localhost has a vhost-admin, second has two vhosts-admins, and third has a vhost-admin:
hosts:
- localhost
- second
- third
acl:
admin:
user: admin1@localhost
append_host_config:
localhost:
acl:
aclhostadmin:
- user: hostadmin@localhost
second:
acl:
aclhostadmin:
- user: hostadmin@second
- user: hostadmin@third
third:
acl:
aclhostadmin:
- user: hostadmin@second
api_permissions:
"vhost http access":
from: mod_http_api
who:
access:
allow:
- acl: admin
allow:
- acl: aclhostadmin
what: "*"Example call of a vhost command by a vhost-admin:
$ curl --basic --user hostadmin@third:somepass -k \
'https://localhost:5443/api/status_num_host?host=second&status=dnd'
7
If a vhost-admin tries to execute an API command directed to a vhost he does not administer, or a global command (that has no host argument, and affects all ejabberd), they are rejected:
$ curl --basic --user hostadmin@third:somepass -k \
'https://localhost:5443/api/status_num_host?host=third&status=dnd'
{"code":32,
"message":"AccessRules: Account does not have the right to perform the operation.",
"status":"error"}
$ curl --basic --user hostadmin@third:somepass -k \
'https://localhost:5443/api/stats?name=registeredusers'
{"code":32,
"message":"AccessRules: Account does not have the right to perform the operation.",
"status":"error"}
ChangeLog
Security fixes
- Unauthenticated Remote Code Execution on ejabberd
- DoS attack on BOSH
- Cross-Tenant MUC, Roster and Shared-Roster unauthorized access
Core
- Add
forcevalue toauth_external_user_exists_checkoption - Add XEP-0158 SHA-256 hashcash CAPTCHA challenge (#4594)
- Add gen_mod:get_module_proc_check()
- Fix to preserve reference order in XML, done in fast_xml and xmpp (#4606)
- Get rid of couple
*_to_atom - Make
ejabberd_cluster:*calloperate only on known nodes - More fixes for arguments in commands for vhost-admin
- Optimize
acl:load_tab() ejabberd_systemd: Prefer matching overlength/1- Updated Portuguese-Brazil and Chinese-Simplified translations
Modules
mod_auth_fast: Make sure that fast tokens can be used only with method that they were created formod_invites: don't apply overuse limit ifmax_invitesisinfinity(#4615)mod_invites: don't crash inget_invite_by_invitee_tifreset_tokenpresent (#4620)mod_invites: now that Conversations is for free we remove Yaxim (#4621)mod_mix: Make access_create rule be applied when creating channelmod_mqtt: Add lower limits for pre-auth packetsmod_muc_room: Fix handling of hats request with missing xdatamod_muc_rtbl: Accept also plain account and domain JIDsmod_muc_rtbl: Fix handling of remote ban servers (#4622)mod_register: After changing password disallow password change on currently authenticated sessions
SQL
- Add
db_serializetomod_privacyandmod_pubsub - Add
rename_columnop toejabbrd_sql_schemaupdate routines - Make
rename_columncompatible with older mysql versions ejabberd_sql_schema: Escape all column/table names- Update
mod_rosterserializer with info about approved field
Administration
- Allow vhost-admin to execute MUC commands for his vhost (#4603)
- Fix method to check vhost-admin permission in Host API (#4619)
- WebAdmin: Fix shared roster page when visited by vhost-admin
- WebAdmin: For vhost-admins, hide useless link to node page
- WebAdmin: Show proper domain in URLs, not the first configured vhost
Installers and Container
make-binaries: Bump Elixir to 1.19.6make-binaries: Bump Erlang/OTP version to 28.5.0.7make-binaries: Bump Expat version to 2.8.5make-binaries: Bump JPEG version to 10make-binaries: Bump OpenSSL 3.6.4make-binaries: Bump PNG version to 1.6.58make-binaries: Bump SQLite version to 3530400make-binaries: Bump WebP version to 1.6.0Dockerfile: Workaround to get image withamd64(#4598)
Full Changelog
Acknowledgments
We would like to thank for the security reports provided by:
- Gia Bui from Calif.io
- Hoang Gia
- Nguyễn Huy Hoàng
- Pham Kiet
- On3nvm
the contributions to the source code by:
- rallep71 for the fixes in
fast_xmlandxmppXML child ordering - MrEddX for fixes in mod_muc_rtbl
- Pounceandmiss for improvement in CAPTCHA
- Stefan Strigler for Invites improvements
- Andreas Aaberge Eide for SQL improvements
- Holger Weiß for installers updates
and the translation by:
- Daltux for updating the Portuguese (Brazil) translation
- Sketch6580 for updating the Chinese (Simplified) translation
And also to all the people contributing in the ejabberd chatroom, issue tracker...
Improvements in ejabberd Business Edition
Customers of the ejabberd Business Edition, in addition to all those bugfixes, also get the following changes:
- Improve p1db serialization
- Fix SQLite backend for push
- Recognize gateway_sandbox option inside
mod_applepushservice (to change sandbox connection endpoint)
Changes in SQL schema
MySQL
When using multihost schema:
ALTER TABLE push_gate CHANGE COLUMN user username text NOT NULL;
CREATE INDEX i_push_gate_username_server_host USING BTREE ON `push_gate`(username(191), server_host(191));Otherwise:
ALTER TABLE push_gate RENAME COLUMN user TO username;
CREATE INDEX i_push_gate_username USING BTREE ON `push_gate`(username(191));PgSql
When using multihost schema:
ALTER TABLE push_gate RENAME COLUMN "user" TO "username";
CREATE INDEX i_push_gate_token_server_host ON "push_gate" USING btree ("username", "server_host");Otherwise:
ALTER TABLE push_gate RENAME COLUMN "user" TO "username";
CREATE INDEX i_push_gate_token ON "push_gate" USING btree ("username");ejabberd 26.09 download & feedback
As usual, the release is tagged in the Git source code repository on GitHub.
The source package and installers are available in ejabberd Downloads page. To check the *.asc signature files, see How to verify ProcessOne downloads integrity.
For convenience, there are alternative download locations like the ejabberd DEB/RPM Packages Repository and the GitHub Release / Tags.
The ecs container image is available in docker.io/ejabberd/ecs and ghcr.io/processone/ecs. The alternative ejabberd container image is available in ghcr.io/processone/ejabberd.
If you consider that you've found a bug, please search or fill a bug report on GitHub Issues.