CVE-2018-21031
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Tautulli versions 2.1.38 and below allows remote attackers to bypass intended access control in Plex Media Server because the X-Plex-Token is mishandled and can be retrieved from Tautulli. NOTE: Initially, this id was associated with Plex Media Server 1.18.2.2029-36236cc4c as the affected product and version. Further research indicated that Tautulli is the correct affected product.
Las versiones 2.1.38 y posteriores de Tautulli permiten a los atacantes remotos eludir el control de acceso previsto en Plex Media Server porque el X-Plex-Token se maneja mal y se puede recuperar de Tautulli. NOTA: Inicialmente, esta identificación estaba asociada con Plex Media Server 1.18.2.2029-36236cc4c como versión y producto afectado. La investigación adicional indicó que Tautulli es el producto afectado correcto.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-11-18 CVE Reserved
- 2019-11-18 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2024-11-11 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-522: Insufficiently Protected Credentials
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://forums.plex.tv/t/security-regarding-cve-2018-21031/493286 | Third Party Advisory | |
https://twitter.com/GerardFuguet/status/1009937529573912576 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.elladodelmal.com/2018/08/shodan-es-de-cine-hacking-tautulli-un.html | 2024-08-05 | |
https://www.exploit-db.com/docs/47790 | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Plex Search vendor "Plex" | Media Server Search vendor "Plex" for product "Media Server" | 1.18.2.2029-36236cc4c Search vendor "Plex" for product "Media Server" and version "1.18.2.2029-36236cc4c" | - |
Affected
|