Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
AVideo Encoder downloadURL SSRF via unpinned retry fallback
Vulnerability Description
AVideo versions from commit 0dbadbca through latest master contain a server-side request forgery vulnerability in the encoder download-by-URL flow due to an unpinned retry fallback that bypasses DNS pinning validation. An authenticated attacker can supply a downloadURL that redirects to an internal address, causing the unpinned retry to follow the redirect and reach internal targets for blind SSRF attacks.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
WWBN AVideo 服务端请求伪造漏洞
Vulnerability Description
WWBN avideo是WWBN组织开源的一套视频内容管理系统。 WWBN AVideo存在服务端请求伪造漏洞,该漏洞源于下载器URL流中的未固定重试回退绕过DNS引脚验证,可能导致经身份验证的攻击者提供指向内部地址的downloadURL,从而盲目服务端请求伪造攻击。
CVSS Information
N/A
Vulnerability Type
N/A