Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2014-8760
ejabberd before 2.1.13 does not enforce the starttls_required setting when compression is used, which causes clients to establish connections without encryption.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.003
EPSS Ranking
49.7%
CVSS Severity
CVSS v2 Score
5.0
References
http://advisories.mageia.org/MGASA-2014-0417.html
http://mail.jabber.org/pipermail/operators/2014-October/002438.html
http://seclists.org/oss-sec/2014/q4/312
http://www.mandriva.com/security/advisories?name=MDVSA-2014:207
http://www.mandriva.com/security/advisories?name=MDVSA-2015:175
http://www.securityfocus.com/bid/70415
https://bugzilla.redhat.com/show_bug.cgi?id=1153839
https://github.com/processone/ejabberd/commit/7bdc1151b
http://advisories.mageia.org/MGASA-2014-0417.html
http://mail.jabber.org/pipermail/operators/2014-October/002438.html
http://seclists.org/oss-sec/2014/q4/312
http://www.mandriva.com/security/advisories?name=MDVSA-2014:207
http://www.mandriva.com/security/advisories?name=MDVSA-2015:175
http://www.securityfocus.com/bid/70415
https://bugzilla.redhat.com/show_bug.cgi?id=1153839
https://github.com/processone/ejabberd/commit/7bdc1151b
Products affected by CVE-2014-8760
Process-One
»
Ejabberd
»
Version:
0.9
cpe:2.3:a:process-one:ejabberd:0.9
Process-One
»
Ejabberd
»
Version:
0.9.1
cpe:2.3:a:process-one:ejabberd:0.9.1
Process-One
»
Ejabberd
»
Version:
0.9.8
cpe:2.3:a:process-one:ejabberd:0.9.8
Process-One
»
Ejabberd
»
Version:
1.0.0
cpe:2.3:a:process-one:ejabberd:1.0.0
Process-One
»
Ejabberd
»
Version:
1.1.0
cpe:2.3:a:process-one:ejabberd:1.1.0
Process-One
»
Ejabberd
»
Version:
1.1.1
cpe:2.3:a:process-one:ejabberd:1.1.1
Process-One
»
Ejabberd
»
Version:
1.1.1.0
cpe:2.3:a:process-one:ejabberd:1.1.1.0
Process-One
»
Ejabberd
»
Version:
1.1.1.1
cpe:2.3:a:process-one:ejabberd:1.1.1.1
Process-One
»
Ejabberd
»
Version:
1.1.14
cpe:2.3:a:process-one:ejabberd:1.1.14
Process-One
»
Ejabberd
»
Version:
1.1.2
cpe:2.3:a:process-one:ejabberd:1.1.2
Process-One
»
Ejabberd
»
Version:
1.1.3
cpe:2.3:a:process-one:ejabberd:1.1.3
Process-One
»
Ejabberd
»
Version:
2.0.0
cpe:2.3:a:process-one:ejabberd:2.0.0
Process-One
»
Ejabberd
»
Version:
2.0.1_2
cpe:2.3:a:process-one:ejabberd:2.0.1_2
Process-One
»
Ejabberd
»
Version:
2.0.2
cpe:2.3:a:process-one:ejabberd:2.0.2
Process-One
»
Ejabberd
»
Version:
2.0.3
cpe:2.3:a:process-one:ejabberd:2.0.3
Process-One
»
Ejabberd
»
Version:
2.0.4
cpe:2.3:a:process-one:ejabberd:2.0.4
Process-One
»
Ejabberd
»
Version:
2.0.5
cpe:2.3:a:process-one:ejabberd:2.0.5
Process-One
»
Ejabberd
»
Version:
2.1.0
cpe:2.3:a:process-one:ejabberd:2.1.0
Process-One
»
Ejabberd
»
Version:
2.1.1
cpe:2.3:a:process-one:ejabberd:2.1.1
Process-One
»
Ejabberd
»
Version:
2.1.10
cpe:2.3:a:process-one:ejabberd:2.1.10
Process-One
»
Ejabberd
»
Version:
2.1.11
cpe:2.3:a:process-one:ejabberd:2.1.11
Process-One
»
Ejabberd
»
Version:
2.1.12
cpe:2.3:a:process-one:ejabberd:2.1.12
Process-One
»
Ejabberd
»
Version:
2.1.2
cpe:2.3:a:process-one:ejabberd:2.1.2
Process-One
»
Ejabberd
»
Version:
2.1.3
cpe:2.3:a:process-one:ejabberd:2.1.3
Process-One
»
Ejabberd
»
Version:
2.1.4
cpe:2.3:a:process-one:ejabberd:2.1.4
Process-One
»
Ejabberd
»
Version:
2.1.5
cpe:2.3:a:process-one:ejabberd:2.1.5
Process-One
»
Ejabberd
»
Version:
2.1.6
cpe:2.3:a:process-one:ejabberd:2.1.6
Process-One
»
Ejabberd
»
Version:
2.1.7
cpe:2.3:a:process-one:ejabberd:2.1.7
Process-One
»
Ejabberd
»
Version:
2.1.8
cpe:2.3:a:process-one:ejabberd:2.1.8
Process-One
»
Ejabberd
»
Version:
2.1.9
cpe:2.3:a:process-one:ejabberd:2.1.9
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved