Authentication Bypass in Plex Media Server by Plex
CVE-2014-9304
Currently unrated
What is CVE-2014-9304?
Plex Media Server, prior to version 0.9.9.3, is susceptible to an authentication bypass vulnerability that can be exploited by remote attackers. These attackers may send specially crafted X-Plex-Url headers to the system/proxy, allowing them to bypass the web server whitelist. This vulnerability can lead to server-side request forgery (SSRF) attacks, enabling malicious users to execute unauthorized administrative actions on the server due to inconsistencies in how the web server's request handler processes these headers. Promptly updating to the latest version is essential to mitigate this risk.
