JabberD 2.x (aka jabberd2) before 2.6.1 allows anyone to authenticate using SASL ANONYMOUS, even when the sasl.anonymous c2s.xml option is not enabled.
[
{
"source": "https://github.com/jabberd2/jabberd2/commit/8416ae54ecefa670534f27a31db71d048b9c7f16",
"deprecated": false,
"signature_type": "Line",
"target": {
"file": "c2s/main.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"142239046814079595553561820321183896380",
"162274436056866001279879458534975722366",
"17621137413520942622358037536706148905"
]
},
"signature_version": "v1",
"id": "CVE-2017-10807-0fb3bb46"
},
{
"source": "https://github.com/jabberd2/jabberd2/commit/8416ae54ecefa670534f27a31db71d048b9c7f16",
"deprecated": false,
"signature_type": "Function",
"target": {
"file": "sx/sasl.c",
"function": "_sx_sasl_client_process"
},
"digest": {
"length": 5706.0,
"function_hash": "116155037334141662439139190908769339120"
},
"signature_version": "v1",
"id": "CVE-2017-10807-45890fe9"
},
{
"source": "https://github.com/jabberd2/jabberd2/commit/8416ae54ecefa670534f27a31db71d048b9c7f16",
"deprecated": false,
"signature_type": "Function",
"target": {
"file": "c2s/main.c",
"function": "_c2s_sx_sasl_callback"
},
"digest": {
"length": 4592.0,
"function_hash": "123546875950137691428725127134889624063"
},
"signature_version": "v1",
"id": "CVE-2017-10807-c1124f54"
},
{
"source": "https://github.com/jabberd2/jabberd2/commit/8416ae54ecefa670534f27a31db71d048b9c7f16",
"deprecated": false,
"signature_type": "Line",
"target": {
"file": "sx/sasl.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"45156698190845962118988405936666210396",
"227331811155657215899841204593333494014",
"285575992947332251203010258925157756072",
"199443385341765755596007736102212356600"
]
},
"signature_version": "v1",
"id": "CVE-2017-10807-e2bd7e93"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-10807.json"