vendor:
Plex Media Server
by:
Stefan Viehböck
N/A
CVSS
CRITICAL
Authentication bypass (SSRF) and local file disclosure
CWE
Product Name: Plex Media Server
Affected Version From: <=0.9.9.2.374-aa23a69
Affected Version To: >=0.9.9.3
Patch Exists: YES
Related CWE:
CPE: plex_media_server
Platforms Tested: Mac OS X, Linux, and Microsoft Windows
2014
Authentication bypass (SSRF) and local file disclosure
The Plex Media Server '/system/proxy' functionality fails to properly validate pre-authentication user requests, allowing unauthenticated attackers to make the Plex Media Server execute arbitrary HTTP requests. By requesting content from 127.0.0.1 an attacker can bypass all authentication and execute commands with administrative privileges. Additionally, due to insufficient input validation, arbitrary local files can be disclosed, including files that contain passwords and other sensitive information.
Mitigation:
Upgrade to version 0.9.9.3 or later.