SRS has command injection vulnerability in demonstration api-server for HTTP callback.
CVE-2023-34105

7.5HIGH

Key Information:

Vendor

ossrs

Status
Vendor
CVE Published:
12 June 2023

What is CVE-2023-34105?

The SRS (Simple Realtime Streaming) video server, known for its support of various streaming protocols, is susceptible to a command injection vulnerability within the 'api-server'. Specifically, this flaw allows an attacker to send requests to the '/api/v1/snapshots' endpoint, embedding arbitrary commands in the body of POST requests. If exploited, this can result in remote code execution, enabling unauthorized control over the affected systems. Versions 5.0.157, 5.0-b1, and 6.0.48 have addressed this vulnerability with patches.

Affected Version(s)

srs >= 5.0.137, < 5.0.157 < 5.0.137, 5.0.157

srs >= 6.0.18, < 6.0.48 < 6.0.18, 6.0.48

srs < 5.0-b1 < 5.0-b1

References

EPSS Score

8% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.