s2s/out.c in jabberd2 2.2.16 and earlier does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domains via a (1) Verify Response or (2) Authorization Response.
CVSS Vector
AV:N/AC:M/Au:N/C:P/I:P/A:NJabber2 Jabberd2
APPJabber22.1.19Jabberd2
APPJabberd22.12.1.12.1.102.1.112.1.122.1.132.1.142.1.152.1.162.1.172.1.182.1.22.1.202.1.212.1.22+ 27 more
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References
Related vulnerabilities
CVE-2017-10807CRITICAL9.8PL ✓same product
Pominięcie uwierzytelnienia przez SASL ANONYMOUS w JabberD 2.x
CVE-2017-18225HIGH7.8same product
The Gentoo net-im/jabberd2 package through 2.6.1 installs jabberd, jabberd2-c2s, jabberd2-router, jabberd2-s2s...
CVE-2011-1755HIGH7.5same product
jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attacke...
CVE-2017-18226MEDIUM5.5same product
The Gentoo net-im/jabberd2 package through 2.6.1 sets the ownership of /var/run/jabber to the jabber account, ...
CVE-2015-2058MEDIUM6.5same product
c2s/c2s.c in Jabber Open Source Server 2.3.2 and earlier truncates data without ensuring it remains valid UTF-...