CVE-2021-32917

An issue was discovered in Prosody before 0.11.9. The proxy65 component allows open access by default, even if neither of the users has an XMPP account on the local server, allowing unrestricted use of the server's bandwidth.
Configurations

Configuration 1 (hide)

cpe:2.3:a:prosody:prosody:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*

History

17 Jun 2021, 16:58

Type Values Removed Values Added
CPE cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
References (MLIST) https://lists.debian.org/debian-lts-announce/2021/06/msg00016.html - (MLIST) https://lists.debian.org/debian-lts-announce/2021/06/msg00016.html - Mailing List, Third Party Advisory

16 Jun 2021, 07:15

Type Values Removed Values Added
References
  • (MLIST) https://lists.debian.org/debian-lts-announce/2021/06/msg00016.html -

26 May 2021, 19:32

Type Values Removed Values Added
CPE cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
References (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GUN63AHEWB2WRROJHU3BVJRWLONCT2B7/ - (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GUN63AHEWB2WRROJHU3BVJRWLONCT2B7/ - Mailing List, Third Party Advisory
References (MISC) https://security.gentoo.org/glsa/202105-15 - (MISC) https://security.gentoo.org/glsa/202105-15 - Third Party Advisory
References (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6MFFBZWXKPZEVZNQSVJNCUE7WRF3T7DG/ - (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6MFFBZWXKPZEVZNQSVJNCUE7WRF3T7DG/ - Mailing List, Third Party Advisory
References (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LWJ2DG2DFJOEFEWOUN26IMYYWGSA2ZEE/ - (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LWJ2DG2DFJOEFEWOUN26IMYYWGSA2ZEE/ - Mailing List, Third Party Advisory

26 May 2021, 11:15

Type Values Removed Values Added
References
  • (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GUN63AHEWB2WRROJHU3BVJRWLONCT2B7/ -
  • (MISC) https://security.gentoo.org/glsa/202105-15 -

22 May 2021, 03:15

Type Values Removed Values Added
References
  • (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6MFFBZWXKPZEVZNQSVJNCUE7WRF3T7DG/ -
  • (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LWJ2DG2DFJOEFEWOUN26IMYYWGSA2ZEE/ -

21 May 2021, 15:23

Type Values Removed Values Added
References (DEBIAN) https://www.debian.org/security/2021/dsa-4916 - (DEBIAN) https://www.debian.org/security/2021/dsa-4916 - Third Party Advisory
References (MLIST) http://www.openwall.com/lists/oss-security/2021/05/13/1 - (MLIST) http://www.openwall.com/lists/oss-security/2021/05/13/1 - Mailing List, Third Party Advisory
References (MLIST) http://www.openwall.com/lists/oss-security/2021/05/14/2 - (MLIST) http://www.openwall.com/lists/oss-security/2021/05/14/2 - Mailing List, Mitigation, Third Party Advisory
References (MISC) https://blog.prosody.im/prosody-0.11.9-released/ - (MISC) https://blog.prosody.im/prosody-0.11.9-released/ - Release Notes, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 4.3
v3 : 5.3
CPE cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:a:prosody:prosody:*:*:*:*:*:*:*:*
CWE CWE-862

Information

Published : 2021-05-13 16:15

Updated : 2024-02-04 21:47


NVD link : CVE-2021-32917

Mitre link : CVE-2021-32917

CVE.ORG link : CVE-2021-32917


JSON object : View

Products Affected

debian

  • debian_linux

prosody

  • prosody

fedoraproject

  • fedora
CWE
CWE-862

Missing Authorization