CVE-2021-32917
Summary
| CVE | CVE-2021-32917 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-05-13 16:15:00 UTC |
| Updated | 2023-11-07 03:35:00 UTC |
| Description | An issue was discovered in Prosody before 0.11.9. The proxy65 component allows open access by default, even if neither of the users has an XMPP account on the local server, allowing unrestricted use of the server's bandwidth. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 34 Update: prosody-0.11.9-1.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Prosody 0.11.9 released | Prosodical Thoughts |
MISC |
blog.prosody.im |
|
| [SECURITY] Fedora 33 Update: prosody-0.11.9-1.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| oss-security - Prosody XMPP server advisory 2021-05-12 (multiple vulnerabilities) |
MLIST |
www.openwall.com |
|
| Debian -- Security Information -- DSA-4916-1 prosody |
DEBIAN |
www.debian.org |
|
| [SECURITY] Fedora 34 Update: prosody-0.11.9-1.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 32 Update: prosody-0.11.9-1.fc32 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 32 Update: prosody-0.11.9-1.fc32 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] [DLA 2687-1] prosody security update |
MLIST |
lists.debian.org |
|
| oss-security - Re: Prosody XMPP server advisory 2021-05-12 (multiple vulnerabilities) |
MLIST |
www.openwall.com |
|
| [SECURITY] Fedora 33 Update: prosody-0.11.9-1.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Prosŏdy IM: Multiple vulnerabilities (GLSA 202105-15) — Gentoo security |
MISC |
security.gentoo.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178602 Debian Security Update for prosody (DSA 4916-1)
- 178674 Debian Security Update for prosody (DLA 2687-1)
- 180374 Debian Security Update for prosody (CVE-2021-32917)
- 281156 Fedora Security Update for prosody (FEDORA-2021-498be8f560)
- 281157 Fedora Security Update for prosody (FEDORA-2021-b5d8c6d086)
- 281158 Fedora Security Update for prosody (FEDORA-2021-a33f6e36e1)
- 501226 Alpine Linux Security Update for prosody
- 690138 Free Berkeley Software Distribution (FreeBSD) Security Update for prosody (fc75570a-b417-11eb-a23d-c7ab331fd711)
- 710569 Gentoo Linux Prosody IM Multiple Vulnerabilities (GLSA 202105-15)
- 750212 OpenSUSE Security Update for prosody (openSUSE-SU-2021:0728-1)