CVE-2021-32920: High severity prosody vulnerability
Prosody before 0.11.9 allows Uncontrolled CPU Consumption via a flood of SSL/TLS renegotiation requests.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-32920?
CVE-2021-32920 is a vulnerability in Prosody before 0.11.9 that allows uncontrolled CPU consumption via a flood of SSL/TLS renegotiation requests.
How severe is CVE-2021-32920?
CVE-2021-32920 has a severity rating of high, with a CVSS score of 7.5.
Which software versions are affected by CVE-2021-32920?
The affected software versions include Prosody 0.11.2-1+deb10u4, 0.11.9-2+deb11u2, 0.12.3-1, and 0.12.4-1.
How can I fix CVE-2021-32920?
To fix CVE-2021-32920, update Prosody to version 0.11.9 or later.
Where can I find more information about CVE-2021-32920?
You can find more information about CVE-2021-32920 at the following references: [http://www.openwall.com/lists/oss-security/2021/05/13/1](http://www.openwall.com/lists/oss-security/2021/05/13/1), [http://www.openwall.com/lists/oss-security/2021/05/14/2](http://www.openwall.com/lists/oss-security/2021/05/14/2), [https://blog.prosody.im/prosody-0.11.9-released/](https://blog.prosody.im/prosody-0.11.9-released/)