Horizon Alert
Summary of the vulnerability and why it matters
A security vulnerability in WWBN AVideo allows unauthenticated access to sensitive user data, including password hashes and session identifiers. This could enable attackers to hijack user sessions and access personal information.
- Unauthenticated users can access sensitive user records.
- Session hijacking and sensitive data access are possible.
- Confirm relevance and exposure for this video platform.
Attack Path
How an attacker could exploit the issue
An attacker can exploit a flaw in how video viewing information is handled to access sensitive user data. By sending a request with a specific parameter, an unauthenticated attacker can retrieve complete user records, including password hashes and active session details. This access can then be leveraged to hijack viewer sessions, even those belonging to administrators, and to steal personal data from all users.
- No authentication is required to access the endpoint.
- A specially crafted request to the videoViewsInfo endpoint triggers the vulnerability.
- Allows session hijacking and theft of sensitive user data.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could expose complete user records, including password hashes, recovery tokens, and live session identifiers, to unauthenticated callers. When a hash parameter is provided to the videoViewsInfo endpoints, this sensitive information can be disclosed.
- User records and session identifiers at risk.
- Disclosed via vulnerable videoViewsInfo endpoints.
- Facilitates session hijacking and data theft.
Operational Fix
Recommended remediation, mitigation, and detection steps
The broken access control vulnerability in WWBN AVideo's videoViewsInfo endpoints presents a critical risk, as it exposes sensitive user data and session identifiers to unauthenticated callers. The platform team, responsible for AVideo's infrastructure, should lead the response by first identifying all instances of AVideo within the environment and confirming their internet accessibility and business criticality. Subsequently, they must identify the accountable application or system owner for each instance to initiate a coordinated remediation plan based on the assessed risk.
- Platform team owns the issue.
- Verify AVideo exposure and criticality.
- Plan remediation based on risk.