See how processone compares to other vendors in security performance
User Impersonation in ProcessOnes XMMP Server ejabberd <= 26.04 allows an attacker to impersonate arbitrary users via unvalidated authzid parameter in SASL-PLAIN mechanism.
It was reported that clients could unexpectedly connect without encryption:
http://mail.jabber.org/pipermail/operators/2014-October/002438.html
Upstream fix (master):
https://github.com/processone/ejabberd/commit/7bdc1151b
References: http://seclists.org/oss-sec/2014/q4/312