Server-to-Server Authentication Vulnerability in Prosody XMPP Server
CVE-2021-32919
7.5HIGH
What is CVE-2021-32919?
A vulnerability exists in Prosody XMPP Server versions before 0.11.9 due to an undocumented feature in mod_dialback that allows remote servers to impersonate other servers. This issue arises from incorrect authentication of remote server certificates when the dialback_without_dialback option is enabled, potentially compromising communication integrity between servers.
