Back to search
CVE-2021-32921
Published: May 13, 2021
Modified: Aug 3, 2024
PUBLISHED
Description
An issue was discovered in Prosody before 0.11.9. It does not use a constant-time algorithm for comparing certain secret strings when running under Lua 5.2 or later. This can potentially be used in a timing attack to reveal the contents of secret strings to an attacker.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://blog.prosody.im/prosody-0.11.9-released/
x_refsource_MISC
[oss-security] 20210513 Prosody XMPP server advisory 2021-05-12 (multiple vulnerabilities)
mailing-list
x_refsource_MLIST
[oss-security] 20210514 Re: Prosody XMPP server advisory 2021-05-12 (multiple vulnerabilities)
mailing-list
x_refsource_MLIST
DSA-4916
vendor-advisory
x_refsource_DEBIAN
FEDORA-2021-b5d8c6d086
vendor-advisory
x_refsource_FEDORA
FEDORA-2021-a33f6e36e1
vendor-advisory
x_refsource_FEDORA
FEDORA-2021-498be8f560
vendor-advisory
x_refsource_FEDORA
https://security.gentoo.org/glsa/202105-15
x_refsource_MISC
[debian-lts-announce] 20210616 [SECURITY] [DLA 2687-1] prosody security update
mailing-list
x_refsource_MLIST
[debian-lts-announce] 20210619 [SECURITY] [DLA 2687-2] prosody regression update
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now