Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-66pq-hqv5-228g

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

Smack allows the bypass of TLS protections

Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allows man-in-the-middle attackers to bypass TLS protections and trigger use of cleartext for client authentication by stripping the "starttls" feature from a server response.

Пакеты

Наименование

org.igniterealtime.smack:smack-core

maven
Затронутые версииВерсия исправления

< 4.1.9

4.1.9

EPSS

Процентиль: 59%
0.00388
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 7.5
redhat
около 9 лет назад

Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allows man-in-the-middle attackers to bypass TLS protections and trigger use of cleartext for client authentication by stripping the "starttls" feature from a server response.

CVSS3: 5.9
nvd
около 9 лет назад

Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allows man-in-the-middle attackers to bypass TLS protections and trigger use of cleartext for client authentication by stripping the "starttls" feature from a server response.

CVSS3: 5.9
debian
около 9 лет назад

Race condition in the XMPP library in Smack before 4.1.9, when the Sec ...

EPSS

Процентиль: 59%
0.00388
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-362