CVE-2021-32919: High severity prosody vulnerability
An issue was discovered in Prosody before 0.11.9. The undocumented dialbackwithoutdialback option in moddialback enables an experimental feature for server-to-server authentication. It does not correctly authenticate remote server certificates, allowing a remote server to impersonate another server (when this option is enabled).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-32919?
CVE-2021-32919 is an issue discovered in Prosody, a XMPP server, before version 0.11.9.
What is the severity of CVE-2021-32919?
CVE-2021-32919 has a severity level of high with a CVSS score of 7.5.
How does CVE-2021-32919 affect Prosody?
CVE-2021-32919 affects Prosody versions before 0.11.9.
What is the vulnerability in CVE-2021-32919?
The vulnerability in CVE-2021-32919 is the undocumented dialback_without_dialback option in mod_dialback, which enables an experimental feature for server-to-server authentication.
How can I fix CVE-2021-32919 in Prosody?
To fix CVE-2021-32919 in Prosody, you should update to version 0.11.9 or later.