Ant Media Server Community Edition in a default configuration is vulnerable to an improper HTTP header based authorization, leading to a possible use of non-administrative API calls reserved only for authorized users.
All versions up to 2.9.0 (tested) and possibly newer ones are believed to be vulnerable as the vendor has not confirmed releasing a patch.
Metrics
Affected Vendors & Products
References
History
Thu, 07 Nov 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Fri, 11 Oct 2024 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 10 Oct 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-863 |
Thu, 10 Oct 2024 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-302 |

Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2024-11-07T15:16:53.084Z
Reserved: 2024-04-08T10:30:37.412Z
Link: CVE-2024-3462

Updated: 2024-08-01T20:12:07.335Z

Status : Awaiting Analysis
Published: 2024-05-14T15:41:14.040
Modified: 2024-11-21T09:29:39.030
Link: CVE-2024-3462

No data.