CVE-2021-32917

An issue was discovered in Prosody before 0.11.9. The proxy65 component allows open access by default, even if neither of the users has an XMPP account on the local server, allowing unrestricted use of the server's bandwidth.
Configurations

Configuration 1 (hide)

cpe:2.3:a:prosody:prosody:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*

History

No history.

Information

Published : 2021-05-13 16:15

Updated : 2023-11-07 03:35


NVD link : CVE-2021-32917

Mitre link : CVE-2021-32917

CVE.ORG link : CVE-2021-32917


JSON object : View

Products Affected

debian

  • debian_linux

fedoraproject

  • fedora

prosody

  • prosody
CWE
CWE-862

Missing Authorization