PT-2022-27427 · Slixmpp+1 · Slixmpp+1

Published

2022-12-10

·

Updated

2025-01-09

·

CVE-2022-45197

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Slixmpp versions prior to 1.8.3
Description The issue lacks SSL Certificate hostname validation in XMLStream, allowing an attacker to pose as any server in the eyes of Slixmpp.
Recommendations For versions prior to 1.8.3, update to version 1.8.3 or later to resolve the issue. As a temporary workaround, consider disabling the XMLStream functionality until a patch is available. Restrict access to the XMLStream module to minimize the risk of exploitation.

Fix

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

CVE-2022-45197
GHSA-Q6CQ-M9GM-6Q2F
MGASA-2022-0469
OPENSUSE-SU-2022:10241-1
OPENSUSE-SU-2022:10242-1
OPENSUSE-SU-2024:12551-1
OPENSUSE-SU-2025:14628-1
PYSEC-2022-43013

Affected Products

Debian
Slixmpp