CVE Published: 13/05/2024 |
CVE Updated: 07/11/2024 |
CVE Year: 2024 Source: CERT-PL |
Vendor: Ant Media |
Product: Ant Media Server Community Edition Status : PUBLISHED
CVE-2024-3462 Description
Ant Media Server Community Edition in a default configuration is vulnerable to an improper HTTP header based authorization, leading to a possible use of non-administrative API calls reserved only for authorized users.
All versions up to 2.9.0 (tested) and possibly newer ones are believed to be vulnerable as the vendor has not confirmed releasing a patch.