PT-2021-21732 · Prosody+1 · Prosody+1

Jonas Schäfer

·

Published

2021-07-28

·

Updated

2024-12-08

·

CVE-2021-37601

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Prosody versions 0.11.0 through 0.11.9
Description The issue allows remote attackers to obtain sensitive information, including the list of admins, members, owners, and banned entities of a Multi-User chat room, in some common configurations. This is due to a problem in the muc.lib.lua module.
Recommendations For Prosody versions 0.11.0 through 0.11.9, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting access to the muc.lib.lua module to minimize the risk of exploitation.

Exploit

Fix

Related Identifiers

ALT-PU-2021-2369
ALT-PU-2021-2552
ALT-PU-2021-2588
ALT-PU-2021-2611
ALT-PU-2024-16554
CVE-2021-37601
OPENSUSE-SU-2021:1173-1
OPENSUSE-SU-2024:11197-1

Affected Products

Alt Linux
Prosody