vulnerability

FreeBSD: VID-fc75570a-b417-11eb-a23d-c7ab331fd711 (CVE-2021-32917): Prosody -- multiple vulnerabilities

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
Published
May 13, 2021
Added
Nov 4, 2022
Modified
Dec 10, 2025

Description

The Prosody security advisory 2021-05-12 reports: This advisory details 5 new security vulnerabilities discovered in the Prosody.im XMPP server software. All issues are fixed in the 0.11.9 release default configuration. CVE-2021-32918: DoS via insufficient memory consumption controls CVE-2021-32920: DoS via repeated TLS renegotiation causing excessive CPU consumption CVE-2021-32921: Use of timing-dependent string comparison with sensitive values CVE-2021-32917: Use of mod_proxy65 is unrestricted in default configuration CVE-2021-32919: Undocumented dialback-without-dialback option insecure

Solution

freebsd-upgrade-package-prosody
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.