CVE Vulnerabilities

CVE-2021-32919

Improper Certificate Validation

Published: May 13, 2021 | Modified: Nov 07, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW

An issue was discovered in Prosody before 0.11.9. The undocumented dialback_without_dialback option in mod_dialback enables an experimental feature for server-to-server authentication. It does not correctly authenticate remote server certificates, allowing a remote server to impersonate another server (when this option is enabled).

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Prosody Prosody 0.10.0 (including) 0.11.9 (excluding)
Prosody Ubuntu bionic *
Prosody Ubuntu esm-apps/bionic *
Prosody Ubuntu esm-apps/focal *
Prosody Ubuntu esm-apps/jammy *
Prosody Ubuntu focal *
Prosody Ubuntu groovy *
Prosody Ubuntu hirsute *
Prosody Ubuntu impish *
Prosody Ubuntu jammy *
Prosody Ubuntu kinetic *
Prosody Ubuntu trusty *
Prosody Ubuntu upstream *
Prosody Ubuntu xenial *

Potential Mitigations

References