
igniterealtime/Smack
Releases47
Frequency2 months 2 weeks
Last Release
Stars2.41K
A modular and portable open source XMPP client library written in Java for Android and Java (SE) VMs
CVE History
| CVE | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|
| 5.9 MEDIUM | 4.3 MEDIUM | ||
Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allows man-in-the-middle attackers to bypass TLS protections and trigger use of cleartext for client authentication by stripping the "starttls" feature from a server response. | |||