ZeroHour

CVE-2022-45197

CVSS 3.1
7.5 high
EPSS
<1%p39
Published
()
Modified
Description

Slixmpp before 1.8.3 lacks SSL Certificate hostname validation in XMLStream, allowing an attacker to pose as any server in the eyes of Slixmpp.

Vendors
slixmpp project
Products
slixmpp
Weakness
CWE-295
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.