Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-444r-2xr3-rxhv

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The ServerTrustManager component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify basicConstraints and nameConstraints in X.509 certificate chains from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate chain.

The ServerTrustManager component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify basicConstraints and nameConstraints in X.509 certificate chains from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate chain.

EPSS

Процентиль: 73%
0.00786
Низкий

Дефекты

CWE-295

Связанные уязвимости

redhat
около 13 лет назад

The ServerTrustManager component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify basicConstraints and nameConstraints in X.509 certificate chains from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate chain.

nvd
почти 12 лет назад

The ServerTrustManager component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify basicConstraints and nameConstraints in X.509 certificate chains from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate chain.

EPSS

Процентиль: 73%
0.00786
Низкий

Дефекты

CWE-295