#VU53314 Improper Authorization in Prosody


Published: 2021-05-17

Vulnerability identifier: #VU53314

Vulnerability risk: Medium

CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-32917

CWE-ID: CWE-285

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
Prosody
Server applications / Mail servers

Vendor: Prosody

Description

The vulnerability allows a remote attacker to use server's bandwidth.

the vulnerability exists within the proxy65 component, which allows open access by default, even if neither of the users has an XMPP account on the local server. A remote attacker can consume the server's bandwidth.


Mitigation
Install updates from vendor's website.

Vulnerable software versions

Prosody: 0.11.0 - 0.11.8


External links
http://blog.prosody.im/prosody-0.11.9-released/
http://www.openwall.com/lists/oss-security/2021/05/13/1
http://www.openwall.com/lists/oss-security/2021/05/14/2


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability