High severity7.5NVD Advisory· Published Jul 30, 2021· Updated Jun 17, 2026
CVE-2021-37601
CVE-2021-37601
Description
muc.lib.lua in Prosody 0.11.0 through 0.11.9 allows remote attackers to obtain sensitive information (list of admins, members, owners, and banned entities of a Multi-User chat room) in some common configurations.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- Prosody/Prosodydescription
- osv-coords3 versionspkg:rpm/opensuse/prosody&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/prosody&distro=openSUSE%20Tumbleweedpkg:rpm/suse/prosody&distro=SUSE%20Package%20Hub%2015%20SP3
< 0.11.10-bp153.2.6.2+ 2 more
- (no CPE)range: < 0.11.10-bp153.2.6.2
- (no CPE)range: < 0.11.10-1.2
- (no CPE)range: < 0.11.10-bp153.2.6.2
Patches
Vulnerability mechanics
References
5- prosody.imnvdExploitProduct
- www.openwall.com/lists/oss-security/2021/07/28/4nvdMailing ListThird Party Advisory
- prosody.im/security/advisory_20210722/nvdVendor Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7BZRRPCNOETB4MN4XSYPRBBKDIHO27DY/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EMKIOEP2CYWHVVUCNWISPE4AGH4IR7O2/nvd
News mentions
0No linked articles in our index yet.