CVE Vulnerabilities

CVE-2022-45197

Improper Certificate Validation

Published: Dec 25, 2022 | Modified: Apr 14, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Slixmpp before 1.8.3 lacks SSL Certificate hostname validation in XMLStream, allowing an attacker to pose as any server in the eyes of Slixmpp.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

NameVendorStart VersionEnd Version
SlixmppSlixmpp_project*1.8.3 (excluding)
SlixmppUbuntubionic*
SlixmppUbuntufocal*
SlixmppUbuntukinetic*
SlixmppUbuntulunar*
SlixmppUbuntutrusty*
SlixmppUbuntuupstream*
SlixmppUbuntuxenial*

Potential Mitigations

References