PT-2024-22679 · Owncast · Owncast
Kevin Stubbings
+1
·
Published
2024-03-20
·
Updated
2025-10-14
·
CVE-2024-29026
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Owncast versions 0.1.2 and prior
Description
Owncast is an open source, self-hosted, decentralized, single user live video streaming and chat server. A lenient CORS policy allows attackers to make a cross origin request, reading privileged information, which can be used to leak the admin password.
Recommendations
For versions 0.1.2 and prior, update to a version that includes the fix from commit 9215d9ba0f29d62201d3feea9e77dcd274581624 to resolve the issue. As a temporary workaround, consider restricting access to sensitive information until the update is applied.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Owncast