CVE-2017-14143: Critical severity kaltura server vulnerability
The getUserzoneCookie function in Kaltura before 13.2.0 uses a hardcoded cookie secret to validate cookie signatures, which allows remote attackers to bypass an intended protection mechanism and consequently conduct PHP object injection attacks and execute arbitrary PHP code via a crafted userzone cookie.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14143?
CVE-2017-14143 is classified as a high severity vulnerability due to its potential for PHP object injection and arbitrary code execution.
How do I fix CVE-2017-14143?
To fix CVE-2017-14143, upgrade Kaltura Server to version 13.2.0 or later where the vulnerability is addressed.
Who is affected by CVE-2017-14143?
CVE-2017-14143 affects Kaltura Server versions up to and including mercury-13.1.0.
What exploitation methods are possible with CVE-2017-14143?
Exploitation of CVE-2017-14143 allows remote attackers to bypass cookie protection and perform PHP object injection attacks.
What are the implications of not addressing CVE-2017-14143?
Failing to address CVE-2017-14143 can lead to unauthorized execution of arbitrary PHP code on the Kaltura Server.