CVE-2021-32917: Medium severity prosody vulnerability
Published May 13, 2021
·Updated
An issue was discovered in Prosody before 0.11.9. The proxy65 component allows open access by default, even if neither of the users has an XMPP account on the local server, allowing unrestricted use of the server's bandwidth.
Affected Software
7 affected componentsFixes available
debian/prosody
0.11.2-1+deb10u40.11.9-2+deb11u20.12.3-10.12.4-1
Prosody prosody<0.11.9
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Fedoraproject Fedora=32
Fedoraproject Fedora=33
Fedoraproject Fedora=34
Event History
May 13, 2021
CVE Published
via MITRE·03:10 PM
Data Sourced
via MITRE·03:10 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2021-32917.
2
What is the severity of CVE-2021-32917?
The severity of CVE-2021-32917 is medium.
3
What is the affected software for CVE-2021-32917?
The affected software for CVE-2021-32917 is Prosody.
4
How can I fix CVE-2021-32917?
You can fix CVE-2021-32917 by updating to Prosody version 0.11.9 or later.
5
Where can I find more information about CVE-2021-32917?
You can find more information about CVE-2021-32917 at the following references: [1](https://www.openwall.com/lists/oss-security/2021/05/13/1), [2](https://prosody.im/security/advisory_20210512.txt), [3](https://hg.prosody.im/trunk/rev/65dcc175ef5b).