AVideo до версии c3edcc274c389816d434acadac07ee78eaf330c1 (master, 23 августа 2026 г.) не обеспечивает принудительной проверки пароля прямой трансляции на конечной точке статистики или в источнике HLS. Live::_getStats() (plugin/Live/Live.php) возвращает ключ потока RTMP передачи, защищенной паролем, его флаг isPasswordProtected и URL-адрес HLS (m3u8) неаутентифицированным вызывающим абонентам как в списке общедоступных приложений, так и в ветви скрытых_приложений, используемой в случае сбоя canSeeLiveFromLiveKey(). Отдельно поставляемая конфигурация NGINX (deploy/nginx/nginx.conf) обслуживает список воспроизведения .m3u8, ключ AES-128 и сегменты транспортного потока из местоположения /live без какого-либо auth_request (директива auth_key_check в расположении .key закомментирована).
Таким образом, удаленный злоумышленник, не прошедший проверку подлинности, может получить ключ потока и ключ дешифрования и посмотреть защищенную паролем прямую трансляцию без предоставления настроенного пароля. На момент публикации исправленной версии не было.
Показать оригинальное описание (EN)
AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) does not enforce the Live stream password check on the stats endpoint or on the HLS origin. Live::_getStats() (plugin/Live/Live.php) returns a password-protected transmission's RTMP stream key, its isPasswordProtected flag, and its HLS (m3u8) URL to unauthenticated callers, in both the public applications list and the hidden_applications branch used when canSeeLiveFromLiveKey() fails. Separately, the shipped NGINX configuration (deploy/nginx/nginx.conf) serves the .m3u8 playlist, the AES-128 key, and the transport-stream segments from the /live location without any auth_request (the auth_key_check directive in the .key location is commented out). A remote, unauthenticated attacker can therefore retrieve the stream key and decryption key and watch a password-protected live transmission without supplying the configured password. No patched version was available at the time of the advisory.
Характеристики атаки
Последствия
Строка CVSS v4.0