CVE-2017-10807: Critical severity jabberd vulnerability
Published Jul 4, 2017
·Updated
JabberD 2.x (aka jabberd2) before 2.6.1 allows anyone to authenticate using SASL ANONYMOUS, even when the sasl.anonymous c2s.xml option is not enabled.
Affected Software
1 affected component
jabberd2 jabberd2<=2.6.0
Event History
Jul 4, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-10807?
CVE-2017-10807 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2017-10807?
To fix CVE-2017-10807, upgrade to JabberD version 2.6.1 or later.
3
What systems are affected by CVE-2017-10807?
CVE-2017-10807 affects JabberD versions prior to 2.6.1.
4
What vulnerability does CVE-2017-10807 expose?
CVE-2017-10807 allows unauthorized users to authenticate using SASL ANONYMOUS.
5
Is CVE-2017-10807 an authenticated or unauthenticated vulnerability?
CVE-2017-10807 is an unauthenticated vulnerability as it allows anyone to authenticate regardless of configuration.