CVE-2014-0363
30.04.2014, 10:49
The ServerTrustManager component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify basicConstraints and nameConstraints in X.509 certificate chains from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate chain.Enginsight
Vendor | Product | Version |
---|---|---|
igniterealtime | smack | 𝑥 < 4.0.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References