Overview
- Description
- Frigate is an open source network video recorder. Prior to version 0.13.0 Beta 3, there is a reflected cross-site scripting vulnerability in any API endpoints reliant on the `/<camera_name>` base path as values provided for the path are not sanitized. Exploiting this vulnerability requires the attacker to both know very specific information about a user's Frigate server and requires an authenticated user to be tricked into clicking a specially crafted link to their Frigate instance. This vulnerability could exploited by an attacker under the following circumstances: Frigate publicly exposed to the internet (even with authentication); attacker knows the address of a user's Frigate instance; attacker crafts a specialized page which links to the user's Frigate instance; attacker finds a way to get an authenticated user to visit their specialized page and click the button/link. As the reflected values included in the URL are not sanitized or escaped, this permits execution arbitrary Javascript payloads. Version 0.13.0 Beta 3 contains a patch for this issue.
- Source
- security-advisories@github.com
- NVD status
- Modified
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 4.7
- Impact score
- 2.7
- Exploitability score
- 1.6
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
- Severity
- MEDIUM
Weaknesses
- security-advisories@github.com
- CWE-79
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:frigate:frigate:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C4732404-ED83-4426-AAA2-7BA34EDDD6BD", "versionEndIncluding": "0.13.0" }, { "criteria": "cpe:2.3:a:frigate:frigate:0.13.0:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C166CCC4-B65F-467C-B9C7-716181142D21" }, { "criteria": "cpe:2.3:a:frigate:frigate:0.13.0:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "950A7EE4-7B30-482E-824D-81BD4DC707F2" } ], "operator": "OR" } ] } ]