CVE-2022-3751
CRITICAL9.8EPSS 0.26%owncast is vulnerable to SQL Injection
發布日:2022/11/29修改日:2025/4/25
描述
SQL Injection in GitHub repository owncast/owncast prior to 0.0.13.
受影響套件(2)
- Go/github.com/owncast/owncastfrom 0, < 0.0.13
- Go/github.com/owncast/owncastfrom 0, < 0.0.13
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
參考連結(8)
- ADVISORYhttps://github.com/advisories/GHSA-cvh4-cjc9-84qm
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2022-3751
- PATCHhttps://github.com/owncast/owncast
- WEBhttps://github.com/owncast/owncast/commit/23b6e5868d5501726c27a3fabbecf49000968591
- WEBhttps://github.com/owncast/owncast/pull/2257
- WEBhttps://huntr.com/bounties/a04cff99-5d53-45e5-a882-771b0fad62c9
- WEBhttps://huntr.dev/bounties/a04cff99-5d53-45e5-a882-771b0fad62c9
- WEBhttps://pkg.go.dev/vuln/GO-2022-1138