ejabberd before 2.1.13 does not enforce the starttls_required setting when compression is used, which causes clients to establish connections without encryption.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ejabberd | Process-one | * | 2.1.12 (including) |
Ejabberd | Ubuntu | artful | * |
Ejabberd | Ubuntu | lucid | * |
Ejabberd | Ubuntu | precise | * |
Ejabberd | Ubuntu | trusty | * |
Ejabberd | Ubuntu | utopic | * |
Ejabberd | Ubuntu | vivid | * |
Ejabberd | Ubuntu | wily | * |
Ejabberd | Ubuntu | yakkety | * |
Ejabberd | Ubuntu | zesty | * |