First published: Wed Jul 28 2021(Updated: )
muc.lib.lua in Prosody 0.11.0 through 0.11.9 allows remote attackers to obtain sensitive information (list of admins, members, owners, and banned entities of a Multi-User chat room) in some common configurations.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Prosody Prosody | >=0.11.0<=0.11.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-37601 is a vulnerability in Prosody 0.11.0 through 0.11.9 that allows remote attackers to obtain sensitive information.
CVE-2021-37601 affects Prosody versions 0.11.0 through 0.11.9.
CVE-2021-37601 has a severity level of 7.5 (High).
CVE-2021-37601 allows remote attackers to obtain sensitive information, specifically a list of admins, members, owners, and banned entities of a Multi-User chat room.
To fix CVE-2021-37601, upgrade your Prosody installation to a version higher than 0.11.9.