GHSA-66pq-hqv5-228g

Suggest an improvement
Source
https://github.com/advisories/GHSA-66pq-hqv5-228g
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-66pq-hqv5-228g/GHSA-66pq-hqv5-228g.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-66pq-hqv5-228g
Aliases
Published
2022-05-13T01:11:39Z
Modified
2025-04-21T23:42:10.681981Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Smack allows the bypass of TLS protections
Details

Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allows man-in-the-middle attackers to bypass TLS protections and trigger use of cleartext for client authentication by stripping the "starttls" feature from a server response.

Database specific
{
    "nvd_published_at": "2017-01-12T23:59:00Z",
    "cwe_ids": [
        "CWE-362"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2025-04-21T22:50:55Z"
}
References

Affected packages

Maven / org.igniterealtime.smack:smack-core

Package

Name
org.igniterealtime.smack:smack-core
View open source insights on deps.dev
Purl
pkg:maven/org.igniterealtime.smack/smack-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.1.9

Affected versions

4.*

4.0.0-rc1
4.0.0-rc2
4.0.0
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.1.0-alpha1
4.1.0-alpha2
4.1.0-alpha3
4.1.0-alpha4
4.1.0-alpha5
4.1.0-alpha6
4.1.0-beta1
4.1.0-beta2
4.1.0-rc1
4.1.0-rc2
4.1.0-rc3
4.1.0-rc4
4.1.0-rc5
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8