An issue was discovered in Prosody before 0.11.9. The proxy65 component allows open access by default, even if neither of the users has an XMPP account on the local server, allowing unrestricted use of the server's bandwidth.
References
Link | Resource |
---|---|
https://blog.prosody.im/prosody-0.11.9-released/ | Release Notes Vendor Advisory |
http://www.openwall.com/lists/oss-security/2021/05/13/1 | Mailing List Third Party Advisory |
http://www.openwall.com/lists/oss-security/2021/05/14/2 | Mailing List Mitigation Third Party Advisory |
https://www.debian.org/security/2021/dsa-4916 | Third Party Advisory |
https://security.gentoo.org/glsa/202105-15 | Third Party Advisory |
https://lists.debian.org/debian-lts-announce/2021/06/msg00016.html | Mailing List Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6MFFBZWXKPZEVZNQSVJNCUE7WRF3T7DG/ | |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LWJ2DG2DFJOEFEWOUN26IMYYWGSA2ZEE/ | |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GUN63AHEWB2WRROJHU3BVJRWLONCT2B7/ |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
07 Nov 2023, 03:35
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2021-05-13 16:15
Updated : 2023-11-07 03:35
NVD link : CVE-2021-32917
Mitre link : CVE-2021-32917
JSON object : View
Products Affected
prosody
- prosody
debian
- debian_linux
fedoraproject
- fedora
CWE
CWE-862
Missing Authorization