First published: Tue Jul 04 2017(Updated: )
JabberD 2.x (aka jabberd2) before 2.6.1 allows anyone to authenticate using SASL ANONYMOUS, even when the sasl.anonymous c2s.xml option is not enabled.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jabberd2 Jabberd2 | <=2.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.