Record summary

CVE-2023-3188 has a selected CVSS score of 6.5 (medium); EIP currently links 1 Nuclei template.

Description

Server-Side Request Forgery (SSRF) in GitHub repository owncast/owncast prior to 0.1.0.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 6, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE ListBefore 0.1.0affected

Nuclei templates

1
ProjectDiscoveryMEDIUMOwncast - Server Side Request ForgeryCVSS 6.5

Server-Side Request Forgery (SSRF) in GitHub repository owncast/owncast prior to 0.1.0.

Impact

Unauthenticated attackers can exploit SSRF through the account parameter in the remotefollow API to probe internal network services and potentially access sensitive internal resources.

Remediation

Update Owncast to version 0.1.0 or later that validates federated account addresses and restricts remote follow requests to authorized domains only.

WeaknessesCWE-918
AuthorsDhiyaneshDk
Template tagscvecve2023owncastoastssrfvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CPE: cpe:2.3:a:owncast_project:owncast:*:*:*:*:*:*:*:*
Shodan: html:"owncast"

Source: ProjectDiscovery

References

3