CVE Vulnerabilities

CVE-2017-10807

Improper Authentication

Published: Jul 04, 2017 | Modified: Nov 04, 2017
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Ubuntu
MEDIUM

JabberD 2.x (aka jabberd2) before 2.6.1 allows anyone to authenticate using SASL ANONYMOUS, even when the sasl.anonymous c2s.xml option is not enabled.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Jabberd2 Jabberd2 * 2.6.0 (including)
Jabberd2 Ubuntu esm-apps/xenial *
Jabberd2 Ubuntu trusty *
Jabberd2 Ubuntu upstream *
Jabberd2 Ubuntu xenial *
Jabberd2 Ubuntu yakkety *
Jabberd2 Ubuntu zesty *

Potential Mitigations

References