Vulnerability Details CVE-2022-24739
alltube is an html front end for youtube-dl. On releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the `stream` option is enabled in the configuration. (This option is disabled by default.) 3.0.3 contains a fix for this vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 46.2%
CVSS Severity
CVSS v3 Score 7.3
CVSS v2 Score 4.0
Products affected by CVE-2022-24739
-
cpe:2.3:a:alltube_project:alltube:0.1
-
cpe:2.3:a:alltube_project:alltube:0.10.0
-
cpe:2.3:a:alltube_project:alltube:0.10.1
-
cpe:2.3:a:alltube_project:alltube:0.10.2
-
cpe:2.3:a:alltube_project:alltube:0.11.0
-
cpe:2.3:a:alltube_project:alltube:0.2
-
cpe:2.3:a:alltube_project:alltube:0.2.1
-
cpe:2.3:a:alltube_project:alltube:0.3.0
-
cpe:2.3:a:alltube_project:alltube:0.3.1
-
cpe:2.3:a:alltube_project:alltube:0.3.2
-
cpe:2.3:a:alltube_project:alltube:0.4.0
-
cpe:2.3:a:alltube_project:alltube:0.4.1
-
cpe:2.3:a:alltube_project:alltube:0.4.2
-
cpe:2.3:a:alltube_project:alltube:0.4.3
-
cpe:2.3:a:alltube_project:alltube:0.4.4
-
cpe:2.3:a:alltube_project:alltube:0.4.5
-
cpe:2.3:a:alltube_project:alltube:0.5.0
-
cpe:2.3:a:alltube_project:alltube:0.5.1
-
cpe:2.3:a:alltube_project:alltube:0.5.2
-
cpe:2.3:a:alltube_project:alltube:0.6.0
-
cpe:2.3:a:alltube_project:alltube:0.7.0
-
cpe:2.3:a:alltube_project:alltube:0.7.1
-
cpe:2.3:a:alltube_project:alltube:0.7.2
-
cpe:2.3:a:alltube_project:alltube:0.8.0
-
cpe:2.3:a:alltube_project:alltube:0.8.1
-
cpe:2.3:a:alltube_project:alltube:0.9.0
-
cpe:2.3:a:alltube_project:alltube:1.0.0
-
cpe:2.3:a:alltube_project:alltube:1.1.0
-
cpe:2.3:a:alltube_project:alltube:1.1.1
-
cpe:2.3:a:alltube_project:alltube:1.1.2
-
cpe:2.3:a:alltube_project:alltube:1.1.3
-
cpe:2.3:a:alltube_project:alltube:1.2.0
-
cpe:2.3:a:alltube_project:alltube:1.2.1
-
cpe:2.3:a:alltube_project:alltube:1.2.2
-
cpe:2.3:a:alltube_project:alltube:1.2.3
-
cpe:2.3:a:alltube_project:alltube:1.2.4
-
cpe:2.3:a:alltube_project:alltube:1.2.5
-
cpe:2.3:a:alltube_project:alltube:2.0.0
-
cpe:2.3:a:alltube_project:alltube:2.0.1
-
cpe:2.3:a:alltube_project:alltube:2.0.2
-
cpe:2.3:a:alltube_project:alltube:2.0.3
-
cpe:2.3:a:alltube_project:alltube:2.0.4
-
cpe:2.3:a:alltube_project:alltube:2.0.5
-
cpe:2.3:a:alltube_project:alltube:2.1.0
-
cpe:2.3:a:alltube_project:alltube:2.2.0
-
cpe:2.3:a:alltube_project:alltube:2.2.1
-
cpe:2.3:a:alltube_project:alltube:2.3.0
-
cpe:2.3:a:alltube_project:alltube:3.0.0
-
cpe:2.3:a:alltube_project:alltube:3.0.1
-
cpe:2.3:a:alltube_project:alltube:3.0.2