CVE-2014-0363: Ignite Realtime Smack
Medium severity, CVSS 5.8. EPSS: 1.2% chance of exploitation in the next 30 days.
The ServerTrustManager component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify basicConstraints and nameConstraints in X.509 certificate chains from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate chain.
Affected products
- Ignite Realtime Smack: before 4.0.0 (fixed in 4.0.0)
Published 2014-04-30. Last modified 2026-06-17.