Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-5075

Опубликовано: 05 авг. 2014
Источник: redhat
CVSS2: 5.8
EPSS Низкий

Описание

The Ignite Realtime Smack XMPP API 4.x before 4.0.2, and 3.x and 2.x when a custom SSLContext is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

It was found that SSLSocket in Smack did not perform hostname verification. An attacker could redirect traffic between an application and an XMPP server by providing a valid certificate for a domain under the attacker's control.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss BRMS 5smackWill not fix
Red Hat JBoss Enterprise Web Server 1fuse-6Under investigation
Red Hat JBoss Enterprise Web Server 1fuse-esb-7Under investigation
Red Hat JBoss Fuse 6.2FixedRHSA-2015:117623.06.2015

Показывать по

Дополнительная информация

Статус:

Moderate

EPSS

Процентиль: 40%
0.00182
Низкий

5.8 Medium

CVSS2

Связанные уязвимости

nvd
больше 11 лет назад

The Ignite Realtime Smack XMPP API 4.x before 4.0.2, and 3.x and 2.x when a custom SSLContext is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

debian
больше 11 лет назад

The Ignite Realtime Smack XMPP API 4.x before 4.0.2, and 3.x and 2.x w ...

github
больше 3 лет назад

The Ignite Realtime Smack XMPP API 4.x before 4.0.2, and 3.x and 2.x when a custom SSLContext is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

EPSS

Процентиль: 40%
0.00182
Низкий

5.8 Medium

CVSS2