ZeroHour

CVE-2017-10807

CVSS 3.0
9.8 critical
EPSS
3%p86
Published
()
Modified
Description

JabberD 2.x (aka jabberd2) before 2.6.1 allows anyone to authenticate using SASL ANONYMOUS, even when the sasl.anonymous c2s.xml option is not enabled.

Vendors
jabberd2
Products
jabberd2
Weakness
CWE-287
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.