Описание
Slixmpp before 1.8.3 lacks SSL Certificate hostname validation in XMLStream, allowing an attacker to pose as any server in the eyes of Slixmpp.
Ссылки
- PatchThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.8.3 (исключая)
cpe:2.3:a:slixmpp_project:slixmpp:*:*:*:*:*:*:*:*
EPSS
Процентиль: 35%
0.00146
Низкий
7.5 High
CVSS3
Дефекты
CWE-295
CWE-295
Связанные уязвимости
CVSS3: 7.5
ubuntu
около 3 лет назад
Slixmpp before 1.8.3 lacks SSL Certificate hostname validation in XMLStream, allowing an attacker to pose as any server in the eyes of Slixmpp.
CVSS3: 7.5
debian
около 3 лет назад
Slixmpp before 1.8.3 lacks SSL Certificate hostname validation in XMLS ...
CVSS3: 7.5
github
около 3 лет назад
Slixmpp lacks SSL Certificate hostname validation in XMLStream
EPSS
Процентиль: 35%
0.00146
Низкий
7.5 High
CVSS3
Дефекты
CWE-295
CWE-295