s2s/out.c in jabberd2 2.2.16 and earlier does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domains via a (1) Verify Response or (2) Authorization Response.
oryginał ENCVSS Vector
AV:N/AC:M/Au:N/C:P/I:P/A:NJabber2 Jabberd2
APPJabber22.1.19Jabberd2
APPJabberd22.12.1.12.1.102.1.112.1.122.1.132.1.142.1.152.1.162.1.172.1.182.1.22.1.202.1.212.1.22+ 27 więcej
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje
Powiązane podatności
CVE-2017-10807CRITICAL9.8PL ✓ten sam produkt
Pominięcie uwierzytelnienia przez SASL ANONYMOUS w JabberD 2.x
CVE-2017-18225HIGH7.8ten sam produkt
The Gentoo net-im/jabberd2 package through 2.6.1 installs jabberd, jabberd2-c2s, jabberd2-router, jabberd2-s2s...
CVE-2011-1755HIGH7.5ten sam produkt
jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attacke...
CVE-2017-18226MEDIUM5.5ten sam produkt
The Gentoo net-im/jabberd2 package through 2.6.1 sets the ownership of /var/run/jabber to the jabber account, ...
CVE-2015-2058MEDIUM6.5ten sam produkt
c2s/c2s.c in Jabber Open Source Server 2.3.2 and earlier truncates data without ensuring it remains valid UTF-...