CVE-2024-3462

Source
https://cve.org/CVERecord?id=CVE-2024-3462
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-3462.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-3462
Aliases
Published
2024-05-13T08:19:13.882Z
Modified
2026-07-15T01:49:21.590973151Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
Authorization bypass in Ant Media Server
Details

Ant Media Server Community Edition in a default configuration is vulnerable to an improper HTTP header based authorization, leading to a possible use of non-administrative API calls reserved only for authorized users.  All versions up to 2.9.0 (tested) and possibly newer ones are believed to be vulnerable as the vendor has not confirmed releasing a patch.

Database specific
{
    "cwe_ids": [
        "CWE-302"
    ],
    "cna_assigner": "CERT-PL",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/3xxx/CVE-2024-3462.json"
}
References

Affected packages

Git / github.com/ant-media/ant-media-server

Affected ranges

Type
GIT
Repo
https://github.com/ant-media/ant-media-server
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.9.0"
        }
    ]
}

Affected versions

ams-v.*
ams-v.1.0M1
ams-v.1.0RC
ams-v1.*
ams-v1.1
ams-v1.1.1
ams-v1.2.0-SNAPSHOT
ams-v1.3.0
ams-v1.3.0-SNAPSHOT
ams-v1.3.3
ams-v1.3.6.1
ams-v1.3.6.2
ams-v1.4.0
ams-v1.4.1
ams-v1.5.0
ams-v1.5.1
ams-v1.5.1.1
ams-v1.5.2
ams-v2.*
ams-v2.9.0
red5+_1.*
red5+_1.0
v1.*
v1.0.2-M1
v1.0.2-RELEASE
v1.0.3-RELEASE
v1.0.4-RELEASE
v1.0.6-RELEASE
v1.0.7-M1
v1.0.7-M10
v1.0.7-M2
v1.0.7-M3
v1.0.7-M4
v1.0.7-M5
v1.0.7-M6
v1.0.7-M7
v1.0.7-M8
v1.0.7-M9
v1.0.7-SNAPSHOT
v1.0.8-M1
v1.0.8-M10
v1.0.8-M11
v1.0.8-M12
v1.0.8-M13
v1.0.8-M2
v1.0.8-M3
v1.0.8-M4
v1.0.8-M6
v1.0.8-M7
v1.0.8-M8
v1.0.8-M9
v1.0.8-RELEASE

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-3462.json"