Vulnerabilities
Vulnerable Software
Process-One:  >> Ejabberd  >> 2.1.8  Security Vulnerabilities
ejabberd before 2.1.13 does not enforce the starttls_required setting when compression is used, which causes clients to establish connections without encryption.
CVSS Score
5.0
EPSS Score
0.003
Published
2014-10-25
The TLS driver in ejabberd before 2.1.12 supports (1) SSLv2 and (2) weak SSL ciphers, which makes it easier for remote attackers to obtain sensitive information via a brute-force attack.
CVSS Score
4.3
EPSS Score
0.004
Published
2013-10-17
The mod_pubsub module (mod_pubsub.erl) in ejabberd 2.1.8 and 3.0.0-alpha-3 allows remote authenticated users to cause a denial of service (infinite loop) via a stanza with a publish tag that lacks a node attribute.
CVSS Score
4.0
EPSS Score
0.012
Published
2012-02-18


Contact Us

Shodan ® - All rights reserved