{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "cpe": "cpe:2.3:a:jabberd2:jabberd2:*:*:*:*:*:*:*:*",
            "extracted_events": [
              {
                "introduced": "0"
              },
              {
                "last_affected": "2.6.0"
              }
            ],
            "source": [
              "CPE_RANGE",
              "REFERENCES"
            ]
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "last_affected": "cf30a83b1366bb914d12963a4be25e9d2587ae43"
            },
            {
              "fixed": "8416ae54ecefa670534f27a31db71d048b9c7f16"
            },
            {
              "fixed": "d3a2b96bea5b36cffd6e4d3e1eb6a47d2586bd1f"
            }
          ],
          "repo": "https://github.com/jabberd2/jabberd2",
          "type": "GIT"
        }
      ]
    }
  ],
  "database_specific": {},
  "details": "JabberD 2.x (aka jabberd2) before 2.6.1 allows anyone to authenticate using SASL ANONYMOUS, even when the sasl.anonymous c2s.xml option is not enabled.",
  "id": "CVE-2017-10807",
  "modified": "2026-07-08T05:38:03.224379749Z",
  "published": "2017-07-04T15:29:00.187Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "http://www.debian.org/security/2017/dsa-3902"
    },
    {
      "type": "ADVISORY",
      "url": "http://www.securityfocus.com/bid/99511"
    },
    {
      "type": "ADVISORY",
      "url": "https://bugs.debian.org/867032"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/jabberd2/jabberd2/commit/8416ae54ecefa670534f27a31db71d048b9c7f16"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/jabberd2/jabberd2/releases/tag/jabberd-2.6.1"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}