U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-31450

Change History

New CVE Received by NIST 4/19/2024 3:15:06 PM

Action Type Old Value New Value
Added CVSS V3.1

								
							
							
						
GitHub, Inc. AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
Added CWE

								
							
							
						
GitHub, Inc. CWE-22
Added Description

								
							
							
						
Owncast is an open source, self-hosted, decentralized, single user live video streaming and chat server. The Owncast application exposes an administrator API at the URL /api/admin. The emoji/delete endpoint of said API allows administrators to delete custom emojis, which are saved on disk. The parameter name is taken from the JSON request and directly appended to the filepath that points to the emoji to delete. By using path traversal sequences (../), attackers with administrative privileges can exploit this endpoint to delete arbitrary files on the system, outside of the emoji directory. This vulnerability is fixed in 0.1.3.
Added Reference

								
							
							
						
GitHub, Inc. https://github.com/owncast/owncast/blob/v0.1.2/controllers/admin/emoji.go#L63 [No types assigned]
Added Reference

								
							
							
						
GitHub, Inc. https://github.com/owncast/owncast/commit/1b14800c7d7f54be14ed4d130bfe7f480645076e [No types assigned]
Added Reference

								
							
							
						
GitHub, Inc. https://github.com/owncast/owncast/releases/tag/v0.1.3 [No types assigned]
Added Reference

								
							
							
						
GitHub, Inc. https://securitylab.github.com/advisories/GHSL-2023-277_Owncast/ [No types assigned]