Horizon Alert
Summary of the vulnerability and why it matters
This critical vulnerability in AVideo allows unauthenticated attackers to access sensitive stream credentials, such as those for YouTube, Facebook, and Twitch, by forging a specific token. The exposure of these credentials could potentially lead to unauthorized use of streaming services or further compromise of user accounts.
- Unauthenticated access to stream credentials.
- External exposure of credentials impacts streaming services.
- Verify if this video platform is in use.
Attack Path
How an attacker could exploit the issue
An attacker can forge a token to bypass authentication and access stream credentials from the AVideo platform. This is achieved by exploiting a public encryption oracle to create a valid token that grants access to sensitive information, such as stream keys and URLs for external platforms like YouTube, Facebook, and Twitch, without requiring any user authentication or special privileges.
- No authentication needed.
- Forge token via public encryption.
- Discloses stream credentials.
Live Threat
Current exploitation, exposure, and threat context
AVideo's Live streaming feature could expose credentials for external platforms like YouTube, Facebook, and Twitch. This occurs when an unauthenticated attacker crafts a specific request to an endpoint that bypasses access controls and ownership checks, allowing disclosure of any restream's stream key and URL. The vulnerability is present when the AVideo application is accessible, and an attacker can interact with the vulnerable endpoint.
- Stream credentials for external platforms.
- Forging tokens to access the endpoint.
- Unauthorized use of streaming services.
Operational Fix
Recommended remediation, mitigation, and detection steps
System owners and application teams are likely responsible for addressing this vulnerability in AVideo, as it exposes sensitive stream credentials through a web endpoint. The first practical step is to identify all instances of AVideo, determine their reachability and business criticality, and then confirm the accountable owner for remediation.
- Identify AVideo deployment owners.
- Verify external exposure and criticality.
- Plan remediation based on risk.