CVE-2017-10807 Information
Feb 14, 2021
cve
Description
JabberD 2.x (aka jabberd2) before 2.6.1 allows anyone to authenticate using SASL ANONYMOUS even when the sasl.anonymous c2s.xml option is not enabled.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
http://www.debian.org/security/2017/dsa-3902 http://www.securityfocus.com/bid/99511 https://bugs.debian.org/867032 https://github.com/jabberd2/jabberd2/commit/8416ae54ecefa670534f27a31db71d048b9c7f16 https://github.com/jabberd2/jabberd2/releases/tag/jabberd-2.6.1
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: