CVE-2021-32917

An issue was discovered in Prosody before 0.11.9. The proxy65 component allows open access by default, even if neither of the users has an XMPP account on the local server, allowing unrestricted use of the server's bandwidth.
References
Link Resource
http://www.openwall.com/lists/oss-security/2021/05/13/1 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2021/05/14/2 Mailing List Mitigation Third Party Advisory
https://blog.prosody.im/prosody-0.11.9-released/ Release Notes Vendor Advisory
https://lists.debian.org/debian-lts-announce/2021/06/msg00016.html Mailing List Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6MFFBZWXKPZEVZNQSVJNCUE7WRF3T7DG/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GUN63AHEWB2WRROJHU3BVJRWLONCT2B7/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LWJ2DG2DFJOEFEWOUN26IMYYWGSA2ZEE/
https://security.gentoo.org/glsa/202105-15 Third Party Advisory
https://www.debian.org/security/2021/dsa-4916 Third Party Advisory
http://www.openwall.com/lists/oss-security/2021/05/13/1 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2021/05/14/2 Mailing List Mitigation Third Party Advisory
https://blog.prosody.im/prosody-0.11.9-released/ Release Notes Vendor Advisory
https://lists.debian.org/debian-lts-announce/2021/06/msg00016.html Mailing List Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6MFFBZWXKPZEVZNQSVJNCUE7WRF3T7DG/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GUN63AHEWB2WRROJHU3BVJRWLONCT2B7/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LWJ2DG2DFJOEFEWOUN26IMYYWGSA2ZEE/
https://security.gentoo.org/glsa/202105-15 Third Party Advisory
https://www.debian.org/security/2021/dsa-4916 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:prosody:prosody:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*

History

No history.

Information

Published : 2021-05-13 16:15

Updated : 2024-11-21 06:07


NVD link : CVE-2021-32917

Mitre link : CVE-2021-32917

CVE.ORG link : CVE-2021-32917


JSON object : View

Products Affected

prosody

  • prosody

debian

  • debian_linux

fedoraproject

  • fedora
CWE
CWE-862

Missing Authorization