Certificate Chain Validation Flaw in Ignite Realtime Smack XMPP API
CVE-2014-0363

Currently unrated

Key Information:

Status
Vendor
CVE Published:
30 April 2014

What is CVE-2014-0363?

The ServerTrustManager component in Ignite Realtime's Smack XMPP API prior to version 4.0.0-rc1 lacks proper validation of both basicConstraints and nameConstraints in X.509 certificate chains. This oversight can be exploited by attackers to execute man-in-the-middle attacks, enabling them to spoof legitimate servers. By presenting a maliciously crafted certificate chain, these attackers can intercept and acquire sensitive information intended for secure communications.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.