CVE-2021-32919 log
Source |
|
Severity | Medium |
Remote | Yes |
Type | Authentication bypass |
Description | A security issue was found in the Prosody.im XMPP server software before version 0.11.9. The undocumented option ‘dialback_without_dialback’ enabled an experimental feature for server-to-server authentication. A flaw in this feature meant it did not correctly authenticate remote servers, allowing a remote server to impersonate another server when this option is enabled. |
Group | Package | Affected | Fixed | Severity | Status | Ticket |
---|---|---|---|---|---|---|
AVG-1955 | prosody | 1:0.11.8-1 | 1:0.11.9-1 | High | Fixed |
Date | Advisory | Group | Package | Severity | Type |
---|---|---|---|---|---|
19 May 2021 | ASA-202105-11 | AVG-1955 | prosody | High | multiple issues |
Notes |
---|
Workaround ========== The issue can be mitigated by removing or disabling the ‘dialback_without_dialback’ option. |