The mod_dialback module in Prosody before 0.9.9 does not properly generate random values for the secret token for server-to-server dialback authentication, which makes it easier for attackers to spoof servers via a brute force attack.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-1232.json"
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "0.9.8"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "0.9.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "0.9.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "0.9.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "0.9.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "0.9.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "0.9.5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "0.9.6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "0.9.7"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "22"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "23"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0"
}
]
}
]