Executive brief
Slixmpp before 1.8.3 lacks SSL Certificate hostname validation in XMLStream, allowing an attacker to pose as any server in the eyes of Slixmpp.
Affected products
- PyPI slixmpp
Junglewise Threat Intelligence
CVE-2022-45197 · Severity: low · CVSS 3.1 · Published 2022-12-25
Technologies: slixmpp (PyPI). Vendors: PyPI.
Slixmpp before 1.8.3 lacks SSL Certificate hostname validation in XMLStream, allowing an attacker to pose as any server in the eyes of Slixmpp.