An issue exists in Prosody prior to 0.11.9. The proxy65 component allows open access by default, even if neither of the users has an XMPP account on the local server, allowing unrestricted use of the server's bandwidth.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
prosody prosody |
||
debian debian linux 9.0 |
||
debian debian linux 10.0 |
||
fedoraproject fedora 32 |
||
fedoraproject fedora 33 |
||
fedoraproject fedora 34 |