Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
prosody prosody vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2011-2531
Prosody 0.8.x prior to 0.8.1, when MySQL is used, assigns an incorrect data type to the value column in certain tables, which might allow remote malicious users to cause a denial of service (data truncation) by sending a large amount of data.
Prosody Prosody 0.8.0
7.5
CVSSv3
CVE-2017-18265
Prosody prior to 0.10.0 allows remote malicious users to cause a denial of service (application crash), related to an incompatibility with certain versions of the LuaSocket library, such as the lua-socket package from Debian stretch. The attacker needs to trigger a stream error. ...
Prosody Prosody
Debian Debian Linux 9.0
7.5
CVSSv3
CVE-2021-32918
An issue exists in Prosody prior to 0.11.9. Default settings are susceptible to remote unauthenticated denial-of-service (DoS) attacks via memory exhaustion when running under Lua 5.2 or Lua 5.3.
Prosody Prosody
Debian Debian Linux 10.0
Fedoraproject Fedora 32
Fedoraproject Fedora 33
Fedoraproject Fedora 34
7.5
CVSSv3
CVE-2021-32920
Prosody prior to 0.11.9 allows Uncontrolled CPU Consumption via a flood of SSL/TLS renegotiation requests.
Prosody Prosody
Debian Debian Linux 10.0
Fedoraproject Fedora 32
Fedoraproject Fedora 33
Fedoraproject Fedora 34
5.9
CVSSv3
CVE-2021-32921
An issue exists in Prosody prior to 0.11.9. It does not use a constant-time algorithm for comparing certain secret strings when running under Lua 5.2 or later. This can potentially be used in a timing attack to reveal the contents of secret strings to an attacker.
Prosody Prosody
Fedoraproject Fedora 32
Fedoraproject Fedora 33
Fedoraproject Fedora 34
Debian Debian Linux 9.0
7.5
CVSSv3
CVE-2021-32919
An issue exists in Prosody prior to 0.11.9. The undocumented dialback_without_dialback option in mod_dialback enables an experimental feature for server-to-server authentication. It does not correctly authenticate remote server certificates, allowing a remote server to impersonat...
Prosody Prosody
Debian Debian Linux 10.0
Fedoraproject Fedora 32
Fedoraproject Fedora 33
Fedoraproject Fedora 34
9.8
CVSSv3
CVE-2020-8086
The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP address passed to the is_admin() function. This grants remote entities admin-only functionality if their username matches the username of a local admin.
Prosody Mod Auth Ldap
Prosody Mod Auth Ldap2
Debian Debian Linux 9.0
Debian Debian Linux 10.0
5.3
CVSSv3
CVE-2021-32917
An issue exists in Prosody prior to 0.11.9. The proxy65 component allows open access by default, even if neither of the users has an XMPP account on the local server, allowing unrestricted use of the server's bandwidth.
Prosody Prosody
Debian Debian Linux 9.0
Debian Debian Linux 10.0
Fedoraproject Fedora 32
Fedoraproject Fedora 33
Fedoraproject Fedora 34
7.5
CVSSv3
CVE-2021-33506
jitsi-meet-prosody in Jitsi Meet prior to 2.0.5963-1 does not ensure that restrict_room_creation is set by default. This can allow an malicious user to circumvent conference moderation.
8x8 Jitsi Meet
7.5
CVSSv3
CVE-2021-39215
Jitsi Meet is an open source video conferencing application. In versions before 2.0.5963, a Prosody module allows the use of symmetrical algorithms to validate JSON web tokens. This means that tokens generated by arbitrary sources can be used to gain authorization to protected ro...
8x8 Jitsi Meet 2.0.5963
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
SSTI
CVE-2024-35863
CVE-2024-35910
man-in-the-middle
CVE-2024-35912
CVE-2024-25742
LFI
CVE-2024-32002
CVE-2024-22120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2