Описание
Coturn is a free open source implementation of TURN and STUN Server. Versions prior to 4.11.0 contain a stored cross-site scripting (XSS) vulnerability in the web-admin HTTPS interface. An attacker who can create a TURN allocation with a crafted USERNAME value can inject HTML/JavaScript that executes when an authenticated web-admin user views the TURN session list. In configurations using anonymous TURN access (--no-auth), this may be exploitable without TURN credentials. In authenticated deployments, exploitation requires valid TURN credentials or control over a provisioned username. This issue has been fixed in version 4.11.0.
A flaw was found in Coturn. A remote attacker can exploit a stored Cross-Site Scripting (XSS) vulnerability in the web-admin HTTPS interface by creating a TURN allocation with a crafted username. This allows the attacker to inject malicious HTML or JavaScript code. When an authenticated web-admin user views the TURN session list, the injected code executes, potentially leading to information disclosure or unauthorized actions within the web-admin interface.
Отчет
This Moderate flaw in Coturn's web-admin HTTPS interface allows a remote attacker to perform stored Cross-Site Scripting. Exploitation requires an attacker to create a TURN allocation with a specially crafted username, which then executes when an authenticated administrator views the TURN session list. While requiring administrator interaction, configurations with anonymous TURN access could broaden the attack surface by not requiring TURN credentials.
Меры по смягчению последствий
Restrict network access to the Coturn web-admin HTTPS interface to trusted administrative networks. Additionally, ensure that Coturn is configured to require authentication for all TURN allocations, preventing unauthenticated users from creating allocations with crafted usernames. This typically involves removing or avoiding the --no-auth option in the Coturn configuration. A restart of the Coturn service is necessary for these configuration changes to take effect.
Дополнительная информация
Статус:
EPSS
5.4 Medium
CVSS3
Связанные уязвимости
Coturn is a free open source implementation of TURN and STUN Server. Versions prior to 4.11.0 contain a stored cross-site scripting (XSS) vulnerability in the web-admin HTTPS interface. An attacker who can create a TURN allocation with a crafted USERNAME value can inject HTML/JavaScript that executes when an authenticated web-admin user views the TURN session list. In configurations using anonymous TURN access (--no-auth), this may be exploitable without TURN credentials. In authenticated deployments, exploitation requires valid TURN credentials or control over a provisioned username. This issue has been fixed in version 4.11.0.
Coturn is a free open source implementation of TURN and STUN Server. Versions prior to 4.11.0 contain a stored cross-site scripting (XSS) vulnerability in the web-admin HTTPS interface. An attacker who can create a TURN allocation with a crafted USERNAME value can inject HTML/JavaScript that executes when an authenticated web-admin user views the TURN session list. In configurations using anonymous TURN access (--no-auth), this may be exploitable without TURN credentials. In authenticated deployments, exploitation requires valid TURN credentials or control over a provisioned username. This issue has been fixed in version 4.11.0.
Coturn is a free open source implementation of TURN and STUN Server. V ...
EPSS
5.4 Medium
CVSS3