SRS has command injection vulnerability in demonstration api-server for HTTP callback.
CVE-2023-34105
7.5HIGH
What is CVE-2023-34105?
The SRS (Simple Realtime Streaming) video server, known for its support of various streaming protocols, is susceptible to a command injection vulnerability within the 'api-server'. Specifically, this flaw allows an attacker to send requests to the '/api/v1/snapshots' endpoint, embedding arbitrary commands in the body of POST requests. If exploited, this can result in remote code execution, enabling unauthorized control over the affected systems. Versions 5.0.157, 5.0-b1, and 6.0.48 have addressed this vulnerability with patches.
Affected Version(s)
srs >= 5.0.137, < 5.0.157 < 5.0.137, 5.0.157
srs >= 6.0.18, < 6.0.48 < 6.0.18, 6.0.48
srs < 5.0-b1 < 5.0-b1
References
EPSS Score
8% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
