Vulnerabilities
7 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-31450 | Owncast is an open source, self-hosted, decentralized, single user live video streaming and chat server. Owncast is an open source, self-hosted, decentralized, single user live video streaming and chat server. The Owncast application exposes an administrator API at the URL /api/admin. The emoji/delete endpoint of said API allows administrators to delete custom emojis, which are saved on disk. The parameter name is taken from the JSON request and directly appended to the filepath that points to the emoji to delete. By using path traversal sequences (../), attackers with administrative privileges can exploit this endpoint to delete arbitrary files on the system, outside of the emoji directory. This vulnerability is fixed in 0.1.3. NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — | |
| CVE-2024-29026 | Owncast is an open source, self-hosted, decentralized, single user live video streaming and chat server. Owncast is an open source, self-hosted, decentralized, single user live video streaming and chat server. In versions 0.1.2 and prior, a lenient CORS policy allows attackers to make a cross origin request, reading privileged information. This can be used to leak the admin password. Commit 9215d9ba0f29d62201d3feea9e77dcd274581624 fixes this issue. NVD description · AI analysis pending | 9.1 | <1% | PoC |
| — | |
| CVE-2024-0305 | A vulnerability was found in Guangzhou Yingke Electronic Technology Ncast up to 2017 and classified as problematic. A vulnerability was found in Guangzhou Yingke Electronic Technology Ncast up to 2017 and classified as problematic. Affected by this issue is some unknown functionality of the file /manage/IPSetup.php of the component Guest Login. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249872. NVD description · AI analysis pending | 7.5 | 67% | PoC |
| — | |
| CVE-2023-46480 | An issue in OwnCast v.0.1.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via the authHost parameter of the indieauth func An issue in OwnCast v.0.1.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via the authHost parameter of the indieauth function. NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2023-3188 | Server-Side Request Forgery (SSRF) in GitHub repository owncast/owncast prior to 0.1.0. Server-Side Request Forgery (SSRF) in GitHub repository owncast/owncast prior to 0.1.0. NVD description · AI analysis pending | 6.5 | 1% | PoC |
| — | |
| CVE-2022-3751 | SQL Injection in GitHub repository owncast/owncast prior to 0.0.13. SQL Injection in GitHub repository owncast/owncast prior to 0.0.13. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2021-39183 | Owncast is an open source, self-hosted live video streaming and chat server. Owncast is an open source, self-hosted live video streaming and chat server. In affected versions inline scripts are executed when Javascript is parsed via a paste action. This issue is patched in 0.0.9 by blocking unsafe-inline Content Security Policy and specifying the script-src. The worker-src is required to be set to blob for the video player. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — |