Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allows man-in-the-middle attackers to bypass TLS protections and trigger use of cleartext for client authentication by stripping the "starttls" feature from a server response.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Smack 竞争条件漏洞
Vulnerability Description
Smack是IgniteRealtime社区的一个开源的XMPP(前称Jabber,即时通讯软件)客户端库。 Smack 4.1.9之前的版本中的XMPP库存在竞争条件漏洞。攻击者可利用该漏洞实施中间人攻击,绕过TLS保护。
CVSS Information
N/A
Vulnerability Type
N/A