Authentication Bypass in Plex Media Server by Plex
CVE-2014-9304

Currently unrated

Key Information:

Vendor

Plex

Vendor
CVE Published:
7 December 2014

What is CVE-2014-9304?

Plex Media Server, prior to version 0.9.9.3, is susceptible to an authentication bypass vulnerability that can be exploited by remote attackers. These attackers may send specially crafted X-Plex-Url headers to the system/proxy, allowing them to bypass the web server whitelist. This vulnerability can lead to server-side request forgery (SSRF) attacks, enabling malicious users to execute unauthorized administrative actions on the server due to inconsistencies in how the web server's request handler processes these headers. Promptly updating to the latest version is essential to mitigate this risk.

References

EPSS Score

8% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.