Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-0363

Опубликовано: 06 фев. 2013
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

The ServerTrustManager component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify basicConstraints and nameConstraints in X.509 certificate chains from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate chain.

It was found that the ServerTrustManager in the Smack XMPP API did not verify basicConstraints and nameConstraints in X.509 certificate chains. A man-in-the-middle attacker could use this flaw to spoof servers and obtain sensitive information.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss BRMS 5smackWill not fix
Red Hat JBoss Enterprise Web Server 1anythingUnder investigation
Red Hat JBoss Enterprise Web Server 1fuse-6Affected
Red Hat JBoss Enterprise Web Server 1fuse-esq-7Will not fix
Red Hat JBoss BPMS 6.0smackFixedRHSA-2014:081930.06.2014
Red Hat JBoss BRMS 6.0smackFixedRHSA-2014:081830.06.2014
Red Hat JBoss Fuse 6.2FixedRHSA-2015:117623.06.2015

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1093273smack: incorrect X.509 certificate validation

EPSS

Процентиль: 73%
0.00786
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

nvd
почти 12 лет назад

The ServerTrustManager component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify basicConstraints and nameConstraints in X.509 certificate chains from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate chain.

github
больше 3 лет назад

The ServerTrustManager component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify basicConstraints and nameConstraints in X.509 certificate chains from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate chain.

EPSS

Процентиль: 73%
0.00786
Низкий

4.3 Medium

CVSS2