CVE-2024-29192
CVE-2024-29192 is a Cross-Site Request Forgery (CSRF) vulnerability in go2rtc versions 1.8.5 and earlier, a camera streaming application. This flaw allows an attacker to potentially modify the application's configuration and execute arbitrary commands by tricking a user into visiting a malicious webpage while authenticated to go2rtc. The /api/config
endpoint, intended for local configuration changes, lacks CSRF protection. Although the SVRS score is 30, the vulnerability could be exploited if go2rtc is configured in a specific manner. If exploited, an attacker can add malicious streams that trigger arbitrary command execution on the server. This security risk highlights the importance of proper configuration and CSRF protection mechanisms. While the CVSS score is 0, the potential for arbitrary command execution makes patching and secure configurations essential. The fix adds a warning about secure API access.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.