There was a local file disclosure vulnerability in AVideo < 8.9 via the proxy streaming. An unauthenticated attacker can exploit this issue to read an arbitrary file on the server. Which could leak database credentials or other sensitive information such as /etc/passwd file.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-11-16T17:03:52
Updated: 2024-08-04T14:58:15.095Z
Reserved: 2020-08-13T00:00:00
Link: CVE-2020-23490
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-11-16T18:15:12.360
Modified: 2024-11-21T05:13:50.123
Link: CVE-2020-23490
Redhat
No data.