CVE-2022-45197

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
25/12/2022
Last modified:
03/05/2023

Description

Slixmpp before 1.8.3 lacks SSL Certificate hostname validation in XMLStream, allowing an attacker to pose as any server in the eyes of Slixmpp.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:slixmpp_project:slixmpp:*:*:*:*:*:*:*:* 1.8.3 (excluding)