Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:10705
HistoryJan 15, 2019 - 8:51 a.m.

Spoofable Domains

2019-01-1508:51:01
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.005 Low

EPSS

Percentile

77.2%

jabberd is vulnerable to spoofable domains. The vulnerability exists as s2s/out.c in jabberd2 2.2.16 and earlier does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domains via a (1) Verify Response or (2) Authorization Response.