Back to search
CVE-2021-37601
Published: Jul 28, 2021
Modified: Aug 4, 2024
PUBLISHED
CVSS v3.1
7.5
HIGH
Description
muc.lib.lua in Prosody 0.11.0 through 0.11.9 allows remote attackers to obtain sensitive information (list of admins, members, owners, and banned entities of a Multi-User chat room) in some common configurations.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AC:L/AV:N/A:N/C:H/I:N/PR:N/S:U/UI:N
Attack Complexity
Low
Attack Vector
Network
Availability
None
Confidentiality
High
Integrity
None
Privileges Required
None
Scope
Unchanged
User Interaction
None
References
https://prosody.im/security/advisory_20210722/
x_refsource_MISC
https://prosody.im/
x_refsource_MISC
[oss-security] 20210728 Re: Prosody XMPP server advisory 2021-07-22 (Remote Information Disclosure) (CVE-2021-37601)
mailing-list
x_refsource_MLIST
FEDORA-2021-1d574ae400
vendor-advisory
x_refsource_FEDORA
FEDORA-2021-fe9513e089
vendor-advisory
x_refsource_FEDORA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now