Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
prosody prosody vulnerabilities and exploits
(subscribe to this query)
7.8
CVSSv2
CVE-2021-32920
Prosody prior to 0.11.9 allows Uncontrolled CPU Consumption via a flood of SSL/TLS renegotiation requests.
Prosody Prosody
Debian Debian Linux 10.0
Fedoraproject Fedora 32
Fedoraproject Fedora 33
Fedoraproject Fedora 34
7.8
CVSSv2
CVE-2014-2744
plugins/mod_compression.lua in (1) Prosody prior to 0.9.4 and (2) Lightwitch Metronome up to and including 3.4 negotiates stream compression while a session is unauthenticated, which allows remote malicious users to cause a denial of service (resource consumption) via compressed ...
Lightwitch Metronome
Prosody Prosody 0.6.2
Prosody Prosody 0.6.0
Prosody Prosody 0.4.1
Prosody Prosody 0.5.0
Prosody Prosody 0.5.1
Prosody Prosody 0.4.2
Prosody Prosody 0.5.2
Prosody Prosody 0.6.1
Prosody Prosody
Prosody Prosody 0.9.1
Prosody Prosody 0.4.0
Prosody Prosody 0.2.0
Prosody Prosody 0.7.0
Prosody Prosody 0.8.1
Prosody Prosody 0.9.0
Prosody Prosody 0.8.2
Prosody Prosody 0.8.0
Prosody Prosody 0.1.0
Prosody Prosody 0.3.0
Prosody Prosody 0.9.2
7.8
CVSSv2
CVE-2014-2745
Prosody prior to 0.9.4 does not properly restrict the processing of compressed XML elements, which allows remote malicious users to cause a denial of service (resource consumption) via a crafted XMPP stream, aka an "xmppbomb" attack, related to core/portmanager.lua and ...
Prosody Prosody 0.8.2
Prosody Prosody 0.8.0
Prosody Prosody 0.1.0
Prosody Prosody 0.3.0
Prosody Prosody 0.9.2
Prosody Prosody 0.6.2
Prosody Prosody 0.6.0
Prosody Prosody 0.4.1
Prosody Prosody 0.5.0
Prosody Prosody 0.5.1
Prosody Prosody 0.4.2
Prosody Prosody 0.5.2
Prosody Prosody 0.6.1
Prosody Prosody
Prosody Prosody 0.9.1
Prosody Prosody 0.4.0
Prosody Prosody 0.2.0
Prosody Prosody 0.7.0
Prosody Prosody 0.8.1
Prosody Prosody 0.9.0
6.8
CVSSv2
CVE-2020-8086
The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP address passed to the is_admin() function. This grants remote entities admin-only functionality if their username matches the username of a local admin.
Prosody Mod Auth Ldap
Prosody Mod Auth Ldap2
Debian Debian Linux 9.0
Debian Debian Linux 10.0
6.5
CVSSv2
CVE-2018-10847
prosody prior to 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass. Prosody did not verify that the virtual host associated with a user session remained the same across stream restarts. A user may authenticate to XMPP host A and migrate their authenticated session to XMPP ...
Prosody Prosody 0.10.0
Prosody Prosody 0.10.1
Prosody Prosody
5
CVSSv2
CVE-2021-39215
Jitsi Meet is an open source video conferencing application. In versions before 2.0.5963, a Prosody module allows the use of symmetrical algorithms to validate JSON web tokens. This means that tokens generated by arbitrary sources can be used to gain authorization to protected ro...
8x8 Jitsi Meet 2.0.5963
5
CVSSv2
CVE-2021-37601
muc.lib.lua in Prosody 0.11.0 up to and including 0.11.9 allows remote malicious users to obtain sensitive information (list of admins, members, owners, and banned entities of a Multi-User chat room) in some common configurations.
Prosody Prosody
5
CVSSv2
CVE-2021-33506
jitsi-meet-prosody in Jitsi Meet prior to 2.0.5963-1 does not ensure that restrict_room_creation is set by default. This can allow an malicious user to circumvent conference moderation.
8x8 Jitsi Meet
5
CVSSv2
CVE-2021-32918
An issue exists in Prosody prior to 0.11.9. Default settings are susceptible to remote unauthenticated denial-of-service (DoS) attacks via memory exhaustion when running under Lua 5.2 or Lua 5.3.
Prosody Prosody
Debian Debian Linux 10.0
Fedoraproject Fedora 32
Fedoraproject Fedora 33
Fedoraproject Fedora 34
5
CVSSv2
CVE-2017-18265
Prosody prior to 0.10.0 allows remote malicious users to cause a denial of service (application crash), related to an incompatibility with certain versions of the LuaSocket library, such as the lua-socket package from Debian stretch. The attacker needs to trigger a stream error. ...
Prosody Prosody
Debian Debian Linux 9.0
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4651
CVE-2024-34255
elevation of privilege
CVE-2024-25529
CVE-2024-4671
NULL pointer dereference
CVE-2024-25527
template injection
CVE-2008-0166
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »