Certificate Chain Validation Flaw in Ignite Realtime Smack XMPP API
CVE-2014-0363
Currently unrated
What is CVE-2014-0363?
The ServerTrustManager component in Ignite Realtime's Smack XMPP API prior to version 4.0.0-rc1 lacks proper validation of both basicConstraints and nameConstraints in X.509 certificate chains. This oversight can be exploited by attackers to execute man-in-the-middle attacks, enabling them to spoof legitimate servers. By presenting a maliciously crafted certificate chain, these attackers can intercept and acquire sensitive information intended for secure communications.
