Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The TLS driver in ejabberd before 2.1.12 supports (1) SSLv2 and (2) weak SSL ciphers, which makes it easier for remote attackers to obtain sensitive information via a brute-force attack.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Ejabberd TLS驱动程序加密问题漏洞
Vulnerability Description
Ejabberd是一款免费、开源且基于Jabber/XMPP协议的即时通讯服务器,它支持跨平台、容错、集群等。 Ejabberd 2.1.12及之前的版本中的TLS驱动程序中存在漏洞,该漏洞源于程序使用SSLv2和弱密码进行通信。远程攻击者可通过暴力破解攻击利用该漏洞获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A