{"id":"CVE-2017-10807","details":"JabberD 2.x (aka jabberd2) before 2.6.1 allows anyone to authenticate using SASL ANONYMOUS, even when the sasl.anonymous c2s.xml option is not enabled.","modified":"2026-07-08T12:05:25.544413Z","published":"2017-07-04T15:29:00.187Z","related":["SUSE-SU-2017:2257-1","SUSE-SU-2017:2266-1","SUSE-SU-2017:2267-1"],"references":[{"type":"ADVISORY","url":"http://www.debian.org/security/2017/dsa-3902"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/99511"},{"type":"ADVISORY","url":"https://bugs.debian.org/867032"},{"type":"ADVISORY","url":"https://github.com/jabberd2/jabberd2/commit/8416ae54ecefa670534f27a31db71d048b9c7f16"},{"type":"ADVISORY","url":"https://github.com/jabberd2/jabberd2/releases/tag/jabberd-2.6.1"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/jabberd2/jabberd2","events":[{"introduced":"0"},{"last_affected":"cf30a83b1366bb914d12963a4be25e9d2587ae43"},{"fixed":"8416ae54ecefa670534f27a31db71d048b9c7f16"},{"fixed":"d3a2b96bea5b36cffd6e4d3e1eb6a47d2586bd1f"}],"database_specific":{"cpe":"cpe:2.3:a:jabberd2:jabberd2:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"2.6.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["jabberd-2.6.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-10807.json","vanir_signatures_modified":"2026-07-08T12:05:25Z","vanir_signatures":[{"digest":{"line_hashes":["142239046814079595553561820321183896380","162274436056866001279879458534975722366","17621137413520942622358037536706148905"],"threshold":0.9},"id":"CVE-2017-10807-0fb3bb46","signature_type":"Line","signature_version":"v1","source":"https://github.com/jabberd2/jabberd2/commit/8416ae54ecefa670534f27a31db71d048b9c7f16","target":{"file":"c2s/main.c"},"deprecated":false},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/jabberd2/jabberd2/commit/8416ae54ecefa670534f27a31db71d048b9c7f16","target":{"function":"_sx_sasl_client_process","file":"sx/sasl.c"},"deprecated":false,"digest":{"length":5706,"function_hash":"116155037334141662439139190908769339120"},"id":"CVE-2017-10807-45890fe9"},{"source":"https://github.com/jabberd2/jabberd2/commit/8416ae54ecefa670534f27a31db71d048b9c7f16","target":{"file":"c2s/main.c","function":"_c2s_sx_sasl_callback"},"deprecated":false,"digest":{"function_hash":"123546875950137691428725127134889624063","length":4592},"id":"CVE-2017-10807-c1124f54","signature_type":"Function","signature_version":"v1"},{"deprecated":false,"digest":{"line_hashes":["45156698190845962118988405936666210396","227331811155657215899841204593333494014","285575992947332251203010258925157756072","199443385341765755596007736102212356600"],"threshold":0.9},"id":"CVE-2017-10807-e2bd7e93","signature_type":"Line","signature_version":"v1","source":"https://github.com/jabberd2/jabberd2/commit/8416ae54ecefa670534f27a31db71d048b9c7f16","target":{"file":"sx/sasl.c"}}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}