The Wocky module in Telepathy Gabble before 0.16.6 and 0.17.x before 0.17.4, when connecting to a "legacy Jabber server," does not properly enforce the WockyConnector:tls-required flag, which allows remote attackers to bypass TLS verification and perform a man-in-the-middle attacks.
CVSS Details
- CVSS 3.1 Base Score: 7.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade telepathy-gabble | Dec 10, 2025 | Jun 5, 2013 |
| Suse | — | Upgrade telepathy-gabbleUpgrade telepathy-gabble-xmpp-console | Dec 12, 2013 | Sep 23, 2013 |
| Ubuntu | — | Upgrade telepathy-gabble | Nov 8, 2024 | Sep 23, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub