PatchSiren cyber security CVE debrief
CVE-2017-5602 Jappix Project CVE debrief
CVE-2017-5602 affects Jappix 1.0.0 through 1.1.6 and stems from an incorrect implementation of XEP-0280 Message Carbons. A remote attacker can cause the application to display messages as if they came from another user, including contacts, which can mislead users and support social engineering attacks.
- Vendor
- Jappix Project
- Product
- Jappix
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-09
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-09
- Advisory updated
- 2026-05-13
Who should care
Administrators of Jappix deployments running 1.0.0-1.1.6, and security teams responsible for chat identity verification, phishing resistance, and client-side trust controls in XMPP environments.
Technical summary
NVD assigns this issue to Jappix versions 1.0.0-1.1.6 and records CVSS 3.0 as AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N, reflecting a network-reachable integrity problem rather than code execution or service disruption. The core flaw is an incorrect Message Carbons handling path that lets a remote party spoof sender identity in the UI, creating a believable impersonation channel for deceptive messages.
Defensive priority
Medium priority. The impact is primarily user deception and message integrity loss, but the attack is remote, requires no privileges, and can be used for convincing social engineering, so exposed deployments should be patched promptly.
Recommended defensive actions
- Upgrade Jappix to a version that includes the upstream fix referenced by the project commit in the advisory trail.
- If immediate upgrade is not possible, review whether Message Carbons can be restricted or disabled in your deployment path.
- Educate users not to trust sensitive requests based only on displayed sender names in chat clients.
- Monitor for suspicious message identity mismatches or conversations that appear to come from contacts but contain unexpected requests.
- Confirm any fix by checking the Jappix release or patch history tied to the referenced GitHub commit.
Evidence notes
The NVD record for CVE-2017-5602 lists Jappix 1.0.0-1.1.6 as vulnerable and provides the CVSS 3.0 vector AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N, with CWE-20 and CWE-346 as the recorded weaknesses. MITRE/NVD references include an Openwall oss-security post, a Jappix GitHub patch commit, a SecurityFocus entry, and RT-Solutions technical advisories describing the XMPP Message Carbons impersonation and social-engineering risk. No evidence in the supplied corpus indicates code execution, data theft, or availability impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-5602 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-5602
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-5602 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5602
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/jappix/jappix/commit/ea6de7c65b80880bdf85df47c1a8a5d3d68491af
[email protected] - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://rt-solutions.de/en/2017/02/CVE-2017-5589_xmpp_carbons/
[email protected] - Exploit, Technical Description, Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://rt-solutions.de/wp-content/uploads/2017/02/CVE-2017-5589_xmpp_carbons.pdf
[email protected] - Exploit, Technical Description, Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.