Описание
Slixmpp lacks SSL Certificate hostname validation in XMLStream
Slixmpp before 1.8.3 lacks SSL Certificate hostname validation in XMLStream, allowing an attacker to pose as any server in the eyes of Slixmpp.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2022-45197
- https://github.com/poezio/slixmpp/commits/master/slixmpp/xmlstream/xmlstream.py
- https://github.com/poezio/slixmpp/tags
- https://github.com/pypa/advisory-database/tree/main/vulns/slixmpp/PYSEC-2022-43013.yaml
- https://lab.louiz.org/poezio/slixmpp/-/commit/b60b1b985db928532f97c4f61d6fbc801f0aa7fa
- https://lab.louiz.org/poezio/slixmpp/-/commits/master
- https://security.gentoo.org/glsa/202305-07
Пакеты
Наименование
slixmpp
pip
Затронутые версииВерсия исправления
< 1.8.3
1.8.3
Связанные уязвимости
CVSS3: 7.5
ubuntu
около 3 лет назад
Slixmpp before 1.8.3 lacks SSL Certificate hostname validation in XMLStream, allowing an attacker to pose as any server in the eyes of Slixmpp.
CVSS3: 7.5
nvd
около 3 лет назад
Slixmpp before 1.8.3 lacks SSL Certificate hostname validation in XMLStream, allowing an attacker to pose as any server in the eyes of Slixmpp.
CVSS3: 7.5
debian
около 3 лет назад
Slixmpp before 1.8.3 lacks SSL Certificate hostname validation in XMLS ...