Debian Prosody vulnerabilities
17 known vulnerabilities affecting debian/prosody.
Total CVEs
17
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH9MEDIUM7LOW1
Vulnerabilities
Page 1 of 1
CVE-2022-0217HIGHCVSS 7.5fixed in prosody 0.11.12-1 (bookworm)2022
CVE-2022-0217 [HIGH] CVE-2022-0217: prosody - It was discovered that an internal Prosody library to load XML based on libexpat...
It was discovered that an internal Prosody library to load XML based on libexpat does not properly restrict the XML features allowed in parsed XML data. Given suitable attacker input, this results in expansion of recursive entity references from DTDs (CWE-776). In addition, depending on the libexpat version used, it may also allow injections using XML External Entity
debian
CVE-2021-32919HIGHCVSS 7.5fixed in prosody 0.11.9-1 (bookworm)2021
CVE-2021-32919 [HIGH] CVE-2021-32919: prosody - An issue was discovered in Prosody before 0.11.9. The undocumented dialback_with...
An issue was discovered in Prosody before 0.11.9. The undocumented dialback_without_dialback option in mod_dialback enables an experimental feature for server-to-server authentication. It does not correctly authenticate remote server certificates, allowing a remote server to impersonate another server (when this option is enabled).
Scope: local
bookworm: resolved (f
debian
CVE-2021-37601HIGHCVSS 7.5fixed in prosody 0.11.9-2 (bookworm)2021
CVE-2021-37601 [HIGH] CVE-2021-37601: prosody - muc.lib.lua in Prosody 0.11.0 through 0.11.9 allows remote attackers to obtain s...
muc.lib.lua in Prosody 0.11.0 through 0.11.9 allows remote attackers to obtain sensitive information (list of admins, members, owners, and banned entities of a Multi-User chat room) in some common configurations.
Scope: local
bookworm: resolved (fixed in 0.11.9-2)
bullseye: resolved (fixed in 0.11.9-2)
forky: resolved (fixed in 0.11.9-2)
sid: resolved (fixed in 0.11
debian
CVE-2021-32920HIGHCVSS 7.5fixed in prosody 0.11.9-1 (bookworm)2021
CVE-2021-32920 [HIGH] CVE-2021-32920: prosody - Prosody before 0.11.9 allows Uncontrolled CPU Consumption via a flood of SSL/TLS...
Prosody before 0.11.9 allows Uncontrolled CPU Consumption via a flood of SSL/TLS renegotiation requests.
Scope: local
bookworm: resolved (fixed in 0.11.9-1)
bullseye: resolved (fixed in 0.11.9-1)
forky: resolved (fixed in 0.11.9-1)
sid: resolved (fixed in 0.11.9-1)
trixie: resolved (fixed in 0.11.9-1)
debian
CVE-2021-32918HIGHCVSS 7.5fixed in prosody 0.11.9-1 (bookworm)2021
CVE-2021-32918 [HIGH] CVE-2021-32918: prosody - An issue was discovered in Prosody before 0.11.9. Default settings are susceptib...
An issue was discovered in Prosody before 0.11.9. Default settings are susceptible to remote unauthenticated denial-of-service (DoS) attacks via memory exhaustion when running under Lua 5.2 or Lua 5.3.
Scope: local
bookworm: resolved (fixed in 0.11.9-1)
bullseye: resolved (fixed in 0.11.9-1)
forky: resolved (fixed in 0.11.9-1)
sid: resolved (fixed in 0.11.9-1)
trixi
debian
CVE-2021-32917MEDIUMCVSS 5.3fixed in prosody 0.11.9-1 (bookworm)2021
CVE-2021-32917 [MEDIUM] CVE-2021-32917: prosody - An issue was discovered in Prosody before 0.11.9. The proxy65 component allows o...
An issue was discovered in Prosody before 0.11.9. The proxy65 component allows open access by default, even if neither of the users has an XMPP account on the local server, allowing unrestricted use of the server's bandwidth.
Scope: local
bookworm: resolved (fixed in 0.11.9-1)
bullseye: resolved (fixed in 0.11.9-1)
forky: resolved (fixed in 0.11.9-1)
sid: resolved
debian
CVE-2021-32921MEDIUMCVSS 5.9fixed in prosody 0.11.9-1 (bookworm)2021
CVE-2021-32921 [MEDIUM] CVE-2021-32921: prosody - An issue was discovered in Prosody before 0.11.9. It does not use a constant-tim...
An issue was discovered in Prosody before 0.11.9. It does not use a constant-time algorithm for comparing certain secret strings when running under Lua 5.2 or later. This can potentially be used in a timing attack to reveal the contents of secret strings to an attacker.
Scope: local
bookworm: resolved (fixed in 0.11.9-1)
bullseye: resolved (fixed in 0.11.9-1)
fork
debian
CVE-2018-10847MEDIUMCVSS 4.2fixed in prosody 0.10.2-1 (bookworm)2018
CVE-2018-10847 [MEDIUM] CVE-2018-10847: prosody - prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass...
prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass. Prosody did not verify that the virtual host associated with a user session remained the same across stream restarts. A user may authenticate to XMPP host A and migrate their authenticated session to XMPP host B of the same Prosody instance.
Scope: local
bookworm: resolved (fixed in
debian
CVE-2017-18265HIGHCVSS 7.5fixed in prosody 0.10.0-1 (bookworm)2017
CVE-2017-18265 [HIGH] CVE-2017-18265: prosody - Prosody before 0.10.0 allows remote attackers to cause a denial of service (appl...
Prosody before 0.10.0 allows remote attackers to cause a denial of service (application crash), related to an incompatibility with certain versions of the LuaSocket library, such as the lua-socket package from Debian stretch. The attacker needs to trigger a stream error. A crash can be observed in, for example, the c2s module.
Scope: local
bookworm: resolved (fixed
debian
CVE-2016-1232HIGHCVSS 7.5fixed in prosody 0.9.9-1 (bookworm)2016
CVE-2016-1232 [HIGH] CVE-2016-1232: prosody - The mod_dialback module in Prosody before 0.9.9 does not properly generate rando...
The mod_dialback module in Prosody before 0.9.9 does not properly generate random values for the secret token for server-to-server dialback authentication, which makes it easier for attackers to spoof servers via a brute force attack.
Scope: local
bookworm: resolved (fixed in 0.9.9-1)
bullseye: resolved (fixed in 0.9.9-1)
forky: resolved (fixed in 0.9.9-1)
sid: resolv
debian
CVE-2016-1231MEDIUMCVSS 5.9fixed in prosody 0.9.9-1 (bookworm)2016
CVE-2016-1231 [MEDIUM] CVE-2016-1231: prosody - Directory traversal vulnerability in the HTTP file-serving module (mod_http_file...
Directory traversal vulnerability in the HTTP file-serving module (mod_http_files) in Prosody 0.9.x before 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) in an unspecified path.
Scope: local
bookworm: resolved (fixed in 0.9.9-1)
bullseye: resolved (fixed in 0.9.9-1)
forky: resolved (fixed in 0.9.9-1)
sid: resolved (fixed in 0.9.9-1)
trixie:
debian
CVE-2016-0756MEDIUMCVSS 5.3fixed in prosody 0.9.10-1 (bookworm)2016
CVE-2016-0756 [MEDIUM] CVE-2016-0756: prosody - The generate_dialback function in the mod_dialback module in Prosody before 0.9....
The generate_dialback function in the mod_dialback module in Prosody before 0.9.10 does not properly separate fields when generating dialback keys, which allows remote attackers to spoof XMPP network domains via a crafted stream id and domain name that is included in the target domain as a suffix.
Scope: local
bookworm: resolved (fixed in 0.9.10-1)
bullseye: resolve
debian
CVE-2014-2744HIGHCVSS 7.8fixed in lua-expat 1.3.0-1 (bookworm)2014
CVE-2014-2744 [HIGH] CVE-2014-2744: lua-expat - plugins/mod_compression.lua in (1) Prosody before 0.9.4 and (2) Lightwitch Metro...
plugins/mod_compression.lua in (1) Prosody before 0.9.4 and (2) Lightwitch Metronome through 3.4 negotiates stream compression while a session is unauthenticated, which allows remote attackers to cause a denial of service (resource consumption) via compressed XML elements in an XMPP stream, aka an "xmppbomb" attack.
Scope: local
bookworm: resolved (fixed in 1.3.0-1)
debian
CVE-2014-2745HIGHCVSS 7.8fixed in prosody 0.9.4-1 (bookworm)2014
CVE-2014-2745 [HIGH] CVE-2014-2745: prosody - Prosody before 0.9.4 does not properly restrict the processing of compressed XML...
Prosody before 0.9.4 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XMPP stream, aka an "xmppbomb" attack, related to core/portmanager.lua and util/xmppstream.lua.
Scope: local
bookworm: resolved (fixed in 0.9.4-1)
bullseye: resolved (fixed in 0.9.4-1
debian
CVE-2011-2532MEDIUMCVSS 5.0fixed in prosody 0.8.1-1 (bookworm)2011
CVE-2011-2532 [MEDIUM] CVE-2011-2532: prosody - The json.decode function in util/json.lua in Prosody 0.8.x before 0.8.1 might al...
The json.decode function in util/json.lua in Prosody 0.8.x before 0.8.1 might allow remote attackers to cause a denial of service (infinite loop) via invalid JSON data, as demonstrated by truncated data.
Scope: local
bookworm: resolved (fixed in 0.8.1-1)
bullseye: resolved (fixed in 0.8.1-1)
forky: resolved (fixed in 0.8.1-1)
sid: resolved (fixed in 0.8.1-1)
trixie:
debian
CVE-2011-2531MEDIUMCVSS 4.3fixed in prosody 0.8.1-1 (bookworm)2011
CVE-2011-2531 [MEDIUM] CVE-2011-2531: prosody - Prosody 0.8.x before 0.8.1, when MySQL is used, assigns an incorrect data type t...
Prosody 0.8.x before 0.8.1, when MySQL is used, assigns an incorrect data type to the value column in certain tables, which might allow remote attackers to cause a denial of service (data truncation) by sending a large amount of data.
Scope: local
bookworm: resolved (fixed in 0.8.1-1)
bullseye: resolved (fixed in 0.8.1-1)
forky: resolved (fixed in 0.8.1-1)
sid: reso
debian
CVE-2011-2205LOWCVSS 6.5fixed in prosody 0.7.0-1 (bookworm)2011
CVE-2011-2205 [MEDIUM] CVE-2011-2205: prosody - Prosody before 0.8.1 does not properly detect recursion during entity expansion,...
Prosody before 0.8.1 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
Scope: local
bookworm: resolved (fixed in 0.7.0-1)
bullseye: resolved (fixed in 0.7
debian