CVE-2023-45671: GHSL-2023-190: Several vulnerabilities in Frigate - CVE-2023-45672, CVE-2023-45671, CVE-2023-45670
Frigate is an open source network video recorder. Prior to version 0.13.0 Beta 3, there is a reflected cross-site scripting vulnerability in any API endpoints reliant on the /<cameraname> base path as values provided for the path are not sanitized. Exploiting this vulnerability requires the attacker to both know very specific information about a user's Frigate server and requires an authenticated user to be tricked into clicking a specially crafted link to their Frigate instance. This vulnerability could exploited by an attacker under the following circumstances: Frigate publicly exposed to the internet (even with authentication); attacker knows the address of a user's Frigate instance; attacker crafts a specialized page which links to the user's Frigate instance; attacker finds a way to get an authenticated user to visit their specialized page and click the button/link. As the reflected values included in the URL are not sanitized or escaped, this permits execution arbitrary Javascript payloads. Version 0.13.0 Beta 3 contains a patch for this issue.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-45671?
CVE-2023-45671 is a reflected cross-site scripting vulnerability in Frigate's API endpoints.
How does CVE-2023-45671 affect Frigate?
CVE-2023-45671 affects Frigate prior to version 0.13.0 Beta 3.
What is the severity of CVE-2023-45671?
CVE-2023-45671 has a severity rating of 4.7 (medium).
How can CVE-2023-45671 be exploited?
CVE-2023-45671 can be exploited by providing unsanitized values for the `/<camera_name>` base path in Frigate's API endpoints, leading to cross-site scripting.
Is there a fix available for CVE-2023-45671?
Yes, upgrading to Frigate version 0.13.0 Beta 3 or newer resolves CVE-2023-45671.