High severity7.5NVD Advisory· Published Dec 25, 2022· Updated Jun 17, 2026
CVE-2022-45197
CVE-2022-45197
Description
Slixmpp before 1.8.3 lacks SSL Certificate hostname validation in XMLStream, allowing an attacker to pose as any server in the eyes of Slixmpp.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
slixmppPyPI | < 1.8.3 | 1.8.3 |
Affected products
7- Slixmpp/Slixmppdescription
- ghsa-coords6 versionspkg:pypi/slixmpppkg:rpm/opensuse/python-slixmpp&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/python-slixmpp&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/python-slixmpp&distro=openSUSE%20Tumbleweedpkg:rpm/suse/python-slixmpp&distro=SUSE%20Package%20Hub%2015%20SP3pkg:rpm/suse/python-slixmpp&distro=SUSE%20Package%20Hub%2015%20SP4
< 1.8.3+ 5 more
- (no CPE)range: < 1.8.3
- (no CPE)range: < 1.4.2-bp153.2.3.1
- (no CPE)range: < 1.4.2-bp154.2.3.1
- (no CPE)range: < 1.8.6-1.1
- (no CPE)range: < 1.4.2-bp153.2.3.1
- (no CPE)range: < 1.4.2-bp154.2.3.1
Patches
Vulnerability mechanics
References
8- github.com/poezio/slixmpp/commits/master/slixmpp/xmlstream/xmlstream.pynvdPatchThird Party AdvisoryWEB
- lab.louiz.org/poezio/slixmpp/-/commit/b60b1b985db928532f97c4f61d6fbc801f0aa7fanvdPatchThird Party AdvisoryWEB
- lab.louiz.org/poezio/slixmpp/-/commits/masternvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-q6cq-m9gm-6q2fghsaADVISORY
- github.com/poezio/slixmpp/tagsnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-45197ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/slixmpp/PYSEC-2022-43013.yamlghsaWEB
- security.gentoo.org/glsa/202305-07nvdWEB
News mentions
0No linked articles in our index yet.