CVE-2021-32919
13.05.2021, 16:15
An issue was discovered in Prosody before 0.11.9. The undocumented dialback_without_dialback option in mod_dialback enables an experimental feature for server-to-server authentication. It does not correctly authenticate remote server certificates, allowing a remote server to impersonate another server (when this option is enabled).Enginsight
Vendor | Product | Version |
---|---|---|
prosody | prosody | 0.10.0 ≤ 𝑥 < 0.11.9 |
debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References