CVE-2021-32919Improper Certificate Validation in Prosody

Severity
7.5HIGHNVD
EPSS
0.4%
top 38.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 13
Latest updateMay 24

Description

An issue was discovered in Prosody before 0.11.9. The undocumented dialback_without_dialback option in mod_dialback enables an experimental feature for server-to-server authentication. It does not correctly authenticate remote server certificates, allowing a remote server to impersonate another server (when this option is enabled).

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

debiandebian/prosody< prosody 0.11.9-1 (bookworm)
NVDprosody/prosody0.10.00.11.9
Debianprosody/prosody< 0.11.9-1+3

Also affects: Debian Linux 10.0, Fedora 32, 33, 34

🔴Vulnerability Details

2
GHSA
GHSA-c9xv-56cc-gjw2: An issue was discovered in Prosody before 02022-05-24
OSV
CVE-2021-32919: An issue was discovered in Prosody before 02021-05-13

📋Vendor Advisories

1
Debian
CVE-2021-32919: prosody - An issue was discovered in Prosody before 0.11.9. The undocumented dialback_with...2021
CVE-2021-32919 — Improper Certificate Validation | cvebase