Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Frigate viewer can read logs exposing admin and camera credentials
Vulnerability Description
Frigate is an open source network video recorder. In version 0.17.1, the GET /api/logs/{service} endpoint allows any authenticated user including the viewer role to download Frigate and nginx logs, exposing auto-generated admin passwords and camera credentials logged in request query strings and enabling viewer-to-admin privilege escalation. A fixed release has not been identified.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
特权管理不恰当
Vulnerability Title
Frigate 权限许可和访问控制问题漏洞
Vulnerability Description
frigate是Frigate团队开源的一款视频分析软件。 Frigate 0.17.1及之前版本存在安全漏洞,该漏洞源于对GET /api/logs/{service}端点的访问控制不足,导致所有认证用户(包括viewer角色)可下载Frigate和nginx日志,从而暴露自动生成的管理员密码和查询字符串中的摄像头凭据,并实现从viewer到admin的权限提升。
CVSS Information
N/A
Vulnerability Type
N/A