CVE-2014-0363: Ignite Realtime Smack

Medium severity, CVSS 5.8. EPSS: 1.2% chance of exploitation in the next 30 days.

The ServerTrustManager component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify basicConstraints and nameConstraints in X.509 certificate chains from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate chain.

Affected products

Published 2014-04-30. Last modified 2026-06-17.