Lucene search

K
nvd[email protected]NVD:CVE-2023-45670
HistoryOct 30, 2023 - 11:15 p.m.

CVE-2023-45670

2023-10-3023:15:08
CWE-352
web.nvd.nist.gov
1
frigate
csrf attack
network video recorder
version 0.13.0 beta 3
security vulnerability

CVSS3

6.8

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:H

EPSS

0.001

Percentile

31.5%

Frigate is an open source network video recorder. Prior to version 0.13.0 Beta 3, the config/save and config/set endpoints of Frigate do not implement any CSRF protection. This makes it possible for a request sourced from another site to update the configuration of the Frigate server (e.g. via “drive-by” attack). Exploiting this vulnerability requires the attacker to both know very specific information about a user’s Frigate server and requires an authenticated user to be tricked into clicking a specially crafted link to their Frigate instance. This vulnerability could exploited by an attacker under the following circumstances: Frigate publicly exposed to the internet (even with authentication); attacker knows the address of a user’s Frigate instance; attacker crafts a specialized page which links to the user’s Frigate instance; attacker finds a way to get an authenticated user to visit their specialized page and click the button/link. This issue can lead to arbitrary configuration updates for the Frigate server, resulting in denial of service and possible data exfiltration. Version 0.13.0 Beta 3 contains a patch.

Affected configurations

Nvd
Node
frigatefrigateRange0.13.0
OR
frigatefrigateMatch0.13.0beta1
OR
frigatefrigateMatch0.13.0beta2
VendorProductVersionCPE
frigatefrigate*cpe:2.3:a:frigate:frigate:*:*:*:*:*:*:*:*
frigatefrigate0.13.0cpe:2.3:a:frigate:frigate:0.13.0:beta1:*:*:*:*:*:*
frigatefrigate0.13.0cpe:2.3:a:frigate:frigate:0.13.0:beta2:*:*:*:*:*:*

CVSS3

6.8

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:H

EPSS

0.001

Percentile

31.5%

Related for NVD:CVE-2023-45670