Kaltura의 mwEmbed 플레이어에 원격 공격자가 파일을 읽고 코드를 실행할 수 있는 취약점이 발견됐다.
CERT/CC는 Kaltura의 HTML5 비디오 플레이어 라이브러리에 두 가지 패치되지 않은 취약점을 공개했다. 이를 통해 인증받지 않은 원격 공격자가 서버의 임의 파일을 읽고 코드를 실행할 수 있다. 이 결함은 mwEmbed 플레이어의 mwEmbedLoader.php 엔드포인트의 안전하지 않은 역직렬화에서 비롯된다.
Unpatched vulnerabilities in Kaltura's mwEmbed allow remote attackers to read files and execute code.
CERT/CC has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library. These flaws allow unauthenticated remote attackers to read arbitrary files from a server and execute code on it. The vulnerabilities stem from unsafe deserialization in the mwEmbedLoader.php endpoint of the mwEmbed player.