Описание
JabberD 2.x (aka jabberd2) before 2.6.1 allows anyone to authenticate using SASL ANONYMOUS, even when the sasl.anonymous c2s.xml option is not enabled.
JabberD 2.x (aka jabberd2) before 2.6.1 allows anyone to authenticate using SASL ANONYMOUS, even when the sasl.anonymous c2s.xml option is not enabled.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2017-10807
- https://github.com/jabberd2/jabberd2/commit/8416ae54ecefa670534f27a31db71d048b9c7f16
- https://bugs.debian.org/867032
- https://github.com/jabberd2/jabberd2/releases/tag/jabberd-2.6.1
- http://www.debian.org/security/2017/dsa-3902
- http://www.securityfocus.com/bid/99511
Связанные уязвимости
JabberD 2.x (aka jabberd2) before 2.6.1 allows anyone to authenticate using SASL ANONYMOUS, even when the sasl.anonymous c2s.xml option is not enabled.
JabberD 2.x (aka jabberd2) before 2.6.1 allows anyone to authenticate using SASL ANONYMOUS, even when the sasl.anonymous c2s.xml option is not enabled.
JabberD 2.x (aka jabberd2) before 2.6.1 allows anyone to authenticate using SASL ANONYMOUS, even when the sasl.anonymous c2s.xml option is not enabled.
JabberD 2.x (aka jabberd2) before 2.6.1 allows anyone to authenticate ...