cbcvebase.
CVE-2021-32917
published 2021-05-13

CVE-2021-32917: An issue was discovered in Prosody before 0.11.9. The proxy65 component allows open access by default, even if neither of the users has an XMPP account on the…

PriorityP430medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
2.17%
80.2th percentile
An issue was discovered in Prosody before 0.11.9. The proxy65 component allows open access by default, even if neither of the users has an XMPP account on the local server, allowing unrestricted use of the server's bandwidth.

Affected

11 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianprosody< prosody 0.11.9-1 (bookworm)prosody 0.11.9-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
prosodyprosody< 0.11.90.11.9
prosodyprosody>= 0 < 0.11.9-10.11.9-1
prosodyprosody>= 0 < 0.11.9-10.11.9-1
prosodyprosody>= 0 < 0.11.9-10.11.9-1
prosodyprosody>= 0 < 0.11.9-10.11.9-1

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.3MEDIUM
vendor_debian5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.