Ant Media Server Community Edition in a default configuration is vulnerable to an improper HTTP header based authorization, leading to a possible use of non-administrative API calls reserved only for authorized users.
All versions up to 2.9.0 (tested) and possibly newer ones are believed to be vulnerable as the vendor has not confirmed releasing a patch.
Metrics
Affected Vendors & Products
References
History
Thu, 07 Nov 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Fri, 11 Oct 2024 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 10 Oct 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-863 |
Thu, 10 Oct 2024 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-302 |
MITRE
Status: PUBLISHED
Assigner: CERT-PL
Published: 2024-05-13T08:19:13.882Z
Updated: 2024-11-07T15:16:53.084Z
Reserved: 2024-04-08T10:30:37.412Z
Link: CVE-2024-3462
Vulnrichment
Updated: 2024-08-01T20:12:07.335Z
NVD
Status : Awaiting Analysis
Published: 2024-05-14T15:41:14.040
Modified: 2024-11-07T16:35:19.013
Link: CVE-2024-3462
Redhat
No data.