Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-0363

Опубликовано: 30 апр. 2014
Источник: nvd
CVSS2: 5.8
EPSS Низкий

Описание

The ServerTrustManager component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify basicConstraints and nameConstraints in X.509 certificate chains from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate chain.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:igniterealtime:smack:*:*:*:*:*:*:*:*
Версия до 4.0.0 (исключая)

EPSS

Процентиль: 73%
0.00786
Низкий

5.8 Medium

CVSS2

Дефекты

CWE-295

Связанные уязвимости

redhat
около 13 лет назад

The ServerTrustManager component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify basicConstraints and nameConstraints in X.509 certificate chains from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate chain.

github
больше 3 лет назад

The ServerTrustManager component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify basicConstraints and nameConstraints in X.509 certificate chains from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate chain.

EPSS

Процентиль: 73%
0.00786
Низкий

5.8 Medium

CVSS2

Дефекты

CWE-295