Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v99w-r56h-g23v

Опубликовано: 05 авг. 2024
Источник: github
Github: Прошло ревью
CVSS4: 8.8
CVSS3: 8.2

Описание

Owncast Cross-Site Request Forgery vulnerability

Owncast is an open source, self-hosted, decentralized, single user live video streaming and chat server. In versions 0.1.2 and prior, a lenient CORS policy allows attackers to make a cross origin request, reading privileged information. This can be used to leak the admin password. Commit 9215d9ba0f29d62201d3feea9e77dcd274581624 fixes this issue.

Пакеты

Наименование

github.com/owncast/owncast

go
Затронутые версииВерсия исправления

<= 0.1.2

0.1.3

EPSS

Процентиль: 35%
0.00142
Низкий

8.8 High

CVSS4

8.2 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.2
nvd
почти 2 года назад

Owncast is an open source, self-hosted, decentralized, single user live video streaming and chat server. In versions 0.1.2 and prior, a lenient CORS policy allows attackers to make a cross origin request, reading privileged information. This can be used to leak the admin password. Commit 9215d9ba0f29d62201d3feea9e77dcd274581624 fixes this issue.

EPSS

Процентиль: 35%
0.00142
Низкий

8.8 High

CVSS4

8.2 High

CVSS3

Дефекты

CWE-352