CVE Vulnerabilities

CVE-2022-45197

Improper Certificate Validation

Published: Dec 25, 2022 | Modified: May 03, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Slixmpp before 1.8.3 lacks SSL Certificate hostname validation in XMLStream, allowing an attacker to pose as any server in the eyes of Slixmpp.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Slixmpp Slixmpp_project * 1.8.3 (excluding)
Slixmpp Ubuntu bionic *
Slixmpp Ubuntu kinetic *
Slixmpp Ubuntu lunar *
Slixmpp Ubuntu trusty *
Slixmpp Ubuntu upstream *
Slixmpp Ubuntu xenial *

Potential Mitigations

References