Critical severity9.8NVD Advisory· Published Jul 4, 2017· Updated May 13, 2026
CVE-2017-10807
CVE-2017-10807
Description
JabberD 2.x (aka jabberd2) before 2.6.1 allows anyone to authenticate using SASL ANONYMOUS, even when the sasl.anonymous c2s.xml option is not enabled.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- www.securityfocus.com/bid/99511nvdThird Party AdvisoryVDB Entry
- bugs.debian.org/867032nvdThird Party Advisory
- github.com/jabberd2/jabberd2/commit/8416ae54ecefa670534f27a31db71d048b9c7f16nvdThird Party Advisory
- github.com/jabberd2/jabberd2/releases/tag/jabberd-2.6.1nvdThird Party Advisory
- www.debian.org/security/2017/dsa-3902nvd
News mentions
0No linked articles in our index yet.