Improper Authorization in Prosody - CVE-2021-32917
Published: May 17, 2021
Vulnerability identifier: #VU53314
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-32917
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to use server's bandwidth.
the vulnerability exists within the proxy65 component, which allows open access by default, even if neither of the users has an XMPP account on the local server. A remote attacker can consume the server's bandwidth.
Affected software
Prosody
Gentoo Linux
Arch Linux
Fedora
prosody (Debian package)
prosody
Gentoo Linux
Arch Linux
Fedora
prosody (Debian package)
prosody
How to mitigate CVE-2021-32917
Install updates from vendor's website.
Prosody - update to 0.11.9
prosody (Debian package) - update to 0.11.2-1+deb10u1
prosody - addressed in versions 0.11.9-1.el7, 0.11.9-1.el8, 0.11.9-1.fc32, 0.11.9-1.fc33, 0.11.9-1.fc34
prosody (Debian package) - update to 0.11.2-1+deb10u1
prosody - addressed in versions 0.11.9-1.el7, 0.11.9-1.el8, 0.11.9-1.fc32, 0.11.9-1.fc33, 0.11.9-1.fc34