Description
Owncast is an open source, self-hosted, decentralized, single user live video streaming and chat server. In versions 0.1.2 and prior, a lenient CORS policy allows attackers to make a cross origin request, reading privileged information. This can be used to leak the admin password. Commit 9215d9ba0f29d62201d3feea9e77dcd274581624 fixes this issue.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2659 | Owncast is an open source, self-hosted, decentralized, single user live video streaming and chat server. In versions 0.1.2 and prior, a lenient CORS policy allows attackers to make a cross origin request, reading privileged information. This can be used to leak the admin password. Commit 9215d9ba0f29d62201d3feea9e77dcd274581624 fixes this issue. |
Github GHSA |
GHSA-v99w-r56h-g23v | Owncast Cross-Site Request Forgery vulnerability |
References
History
Tue, 14 Oct 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Owncast Project
Owncast Project owncast |
|
| CPEs | cpe:2.3:a:owncast_project:owncast:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Owncast Project
Owncast Project owncast |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T01:03:51.653Z
Reserved: 2024-03-14T16:59:47.611Z
Link: CVE-2024-29026
Updated: 2024-08-02T01:03:51.653Z
Status : Analyzed
Published: 2024-03-20T22:15:08.557
Modified: 2025-10-14T17:01:44.903
Link: CVE-2024-29026
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA