CVE-2021-32919 log
| Source |
|
| Severity | Medium |
| Remote | Yes |
| Type | Authentication bypass |
| Description | A security issue was found in the Prosody.im XMPP server software before version 0.11.9. The undocumented option ‘dialback_without_dialback’ enabled an experimental feature for server-to-server authentication. A flaw in this feature meant it did not correctly authenticate remote servers, allowing a remote server to impersonate another server when this option is enabled. |
| Group | Package | Affected | Fixed | Severity | Status | Ticket |
|---|---|---|---|---|---|---|
| AVG-1955 | prosody | 1:0.11.8-1 | 1:0.11.9-1 | High | Fixed |
| Date | Advisory | Group | Package | Severity | Type |
|---|---|---|---|---|---|
| 19 May 2021 | ASA-202105-11 | AVG-1955 | prosody | High | multiple issues |
| Notes |
|---|
Workaround ========== The issue can be mitigated by removing or disabling the ‘dialback_without_dialback’ option. |