Ant Media Server Community Edition in a default configuration is vulnerable to an improper HTTP header based authorization, leading to a possible use of non-administrative API calls reserved only for authorized users. 
All versions up to 2.9.0 (tested) and possibly newer ones are believed to be vulnerable as the vendor has not confirmed releasing a patch.
                
            Metrics
Affected Vendors & Products
References
        History
                    Thu, 07 Nov 2024 16:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        cvssV3_1
         
  | 
Fri, 11 Oct 2024 21:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Thu, 10 Oct 2024 16:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-863 | 
Thu, 10 Oct 2024 15:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-302 | 
Status: PUBLISHED
Assigner: CERT-PL
Published: 2024-05-13T08:19:13.882Z
Updated: 2024-11-07T15:16:53.084Z
Reserved: 2024-04-08T10:30:37.412Z
Link: CVE-2024-3462
Updated: 2024-08-01T20:12:07.335Z
Status : Awaiting Analysis
Published: 2024-05-14T15:41:14.040
Modified: 2024-11-21T09:29:39.030
Link: CVE-2024-3462
No data.