First published: Thu May 13 2021(Updated: )
An issue was discovered in Prosody before 0.11.9. The undocumented dialback_without_dialback option in mod_dialback enables an experimental feature for server-to-server authentication. It does not correctly authenticate remote server certificates, allowing a remote server to impersonate another server (when this option is enabled).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/prosody | 0.11.2-1+deb10u4 0.11.9-2+deb11u2 0.12.3-1 0.12.4-1 | |
Prosody Prosody | >=0.10.0<0.11.9 | |
Debian Debian Linux | =10.0 | |
Fedoraproject Fedora | =32 | |
Fedoraproject Fedora | =33 | |
Fedoraproject Fedora | =34 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-32919 is an issue discovered in Prosody, a XMPP server, before version 0.11.9.
CVE-2021-32919 has a severity level of high with a CVSS score of 7.5.
CVE-2021-32919 affects Prosody versions before 0.11.9.
The vulnerability in CVE-2021-32919 is the undocumented dialback_without_dialback option in mod_dialback, which enables an experimental feature for server-to-server authentication.
To fix CVE-2021-32919 in Prosody, you should update to version 0.11.9 or later.