Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-10027

Опубликовано: 12 нояб. 2016
Источник: redhat
CVSS3: 7.5
CVSS2: 5.4

Описание

Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allows man-in-the-middle attackers to bypass TLS protections and trigger use of cleartext for client authentication by stripping the "starttls" feature from a server response.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss BRMS 5smackWill not fix
Red Hat JBoss Fuse 6camelWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1406703smack: TLS SecurityMode.required bypass via StripTLS attack

7.5 High

CVSS3

5.4 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.9
nvd
около 9 лет назад

Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allows man-in-the-middle attackers to bypass TLS protections and trigger use of cleartext for client authentication by stripping the "starttls" feature from a server response.

CVSS3: 5.9
debian
около 9 лет назад

Race condition in the XMPP library in Smack before 4.1.9, when the Sec ...

CVSS3: 5.9
github
больше 3 лет назад

Smack allows the bypass of TLS protections

7.5 High

CVSS3

5.4 Medium

CVSS2