CVE-2023-3188
Server-Side Request Forgery (SSRF) in owncast/owncast
Record summary
CVE-2023-3188 has a selected CVSS score of 6.5 (medium); EIP currently links 1 Nuclei template.
Description
Server-Side Request Forgery (SSRF) in GitHub repository owncast/owncast prior to 0.1.0.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 6, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
owncast/owncastBrowse owncast / owncast/owncast | CVE List | Before 0.1.0 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMOwncast - Server Side Request ForgeryCVSS 6.5
Server-Side Request Forgery (SSRF) in GitHub repository owncast/owncast prior to 0.1.0.
Impact
Unauthenticated attackers can exploit SSRF through the account parameter in the remotefollow API to probe internal network services and potentially access sensitive internal resources.
Remediation
Update Owncast to version 0.1.0 or later that validates federated account addresses and restricts remote follow requests to authorized domains only.
Source: ProjectDiscovery