An issue was discovered in Prosody before 0.11.9. The undocumented dialback_without_dialback option in mod_dialback enables an experimental feature for server-to-server authentication. It does not correctly authenticate remote server certificates, allowing a remote server to impersonate another server (when this option is enabled).
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2021-05-13T15:12:19

Updated: 2024-08-03T23:33:55.965Z

Reserved: 2021-05-12T00:00:00

Link: CVE-2021-32919

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-05-13T16:15:08.347

Modified: 2023-11-07T03:35:45.287

Link: CVE-2021-32919

cve-icon Redhat

No data.