Timing Attack Vulnerability in Prosody XMPP Server
CVE-2021-32921

5.9MEDIUM

Key Information:

Vendor

Prosody

Status
Vendor
CVE Published:
13 May 2021

What is CVE-2021-32921?

A vulnerability was found in Prosody versions before 0.11.9, where the software fails to implement a constant-time algorithm for secret string comparisons when using Lua 5.2 or later. This oversight can be exploited in a timing attack, potentially allowing attackers to glean information about sensitive secret strings, posing a significant risk to the confidentiality of communications facilitated by the Prosody server.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.