CVE-2017-10807

Source
https://cve.org/CVERecord?id=CVE-2017-10807
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-10807.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-10807
Downstream
DEBIAN (1)
SUSE (3)
UBUNTU (1)
Related
Published
2017-07-04T15:29:00Z
Modified
2026-07-08T12:05:25Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

JabberD 2.x (aka jabberd2) before 2.6.1 allows anyone to authenticate using SASL ANONYMOUS, even when the sasl.anonymous c2s.xml option is not enabled.

References

Affected packages

Git / github.com/jabberd2/jabberd2

Affected ranges

Type
GIT
Repo
https://github.com/jabberd2/jabberd2
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last Affected
Fixed
Fixed
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:jabberd2:jabberd2:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "last_affected":  "2.6.0"
        }
    ],
    "source":  [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

jabberd-2.*
jabberd-2.6.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-10807.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "142239046814079595553561820321183896380",
                "162274436056866001279879458534975722366",
                "17621137413520942622358037536706148905"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2017-10807-0fb3bb46",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/jabberd2/jabberd2/commit/8416ae54ecefa670534f27a31db71d048b9c7f16",
        "target":  {
            "file":  "c2s/main.c"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "116155037334141662439139190908769339120",
            "length":  5706
        },
        "id":  "CVE-2017-10807-45890fe9",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/jabberd2/jabberd2/commit/8416ae54ecefa670534f27a31db71d048b9c7f16",
        "target":  {
            "file":  "sx/sasl.c",
            "function":  "_sx_sasl_client_process"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "123546875950137691428725127134889624063",
            "length":  4592
        },
        "id":  "CVE-2017-10807-c1124f54",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/jabberd2/jabberd2/commit/8416ae54ecefa670534f27a31db71d048b9c7f16",
        "target":  {
            "file":  "c2s/main.c",
            "function":  "_c2s_sx_sasl_callback"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "45156698190845962118988405936666210396",
                "227331811155657215899841204593333494014",
                "285575992947332251203010258925157756072",
                "199443385341765755596007736102212356600"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2017-10807-e2bd7e93",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/jabberd2/jabberd2/commit/8416ae54ecefa670534f27a31db71d048b9c7f16",
        "target":  {
            "file":  "sx/sasl.c"
        }
    }
]
vanir_signatures_modified
"2026-07-08T12:05:25Z"