Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in Kaltura before 13.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) partnerId or (2) playerVersion parameter to server/admin_console/web/tools/bigRedButton.php; the (3) partnerId, (4) playerVersion, (5) secret, (6) entryId, (7) adminUiConfId, or (8) uiConfId parameter to server/admin_console/web/tools/bigRedButtonPtsPoc.php; the (9) streamUsername, (10) streamPassword, (11) streamRemoteId, (12) streamRemoteBackupId, or (13) entryId parameter to server/admin_console/web/tools/AkamaiBroadcaster.php; the (14) entryId parameter to server/admin_console/web/tools/XmlJWPlayer.php; or the (15) partnerId or (16) playerVersion parameter to server/alpha/web/lib/bigRedButtonPtsPocHlsjs.php.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kaltura | Kaltura Server | <= mercury-13.1.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/100976Third Party AdvisoryVDB Entry
- https://github.com/kaltura/server/pull/6003/commits/7e00a578d6ba748f6d3bdc255a40Third Party Advisory
- https://github.com/kaltura/server/pull/6003/commits/a63362aa87d668d5ebf4a89cdd5bThird Party Advisory
- https://telekomsecurity.github.io/assets/advisories/20170912_kaltura-advisory.txExploitThird Party Advisory
- http://www.securityfocus.com/bid/100976Third Party AdvisoryVDB Entry
- https://github.com/kaltura/server/pull/6003/commits/7e00a578d6ba748f6d3bdc255a40Third Party Advisory
- https://github.com/kaltura/server/pull/6003/commits/a63362aa87d668d5ebf4a89cdd5bThird Party Advisory
- https://telekomsecurity.github.io/assets/advisories/20170912_kaltura-advisory.txExploitThird Party Advisory
FAQ
What is CVE-2017-14142?
CVE-2017-14142 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Multiple cross-site scripting (XSS) vulnerabilities in Kaltura before 13.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) partnerId or (2) playerVersion parameter to serve...
How severe is CVE-2017-14142?
CVE-2017-14142 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-14142?
Check the references section above for vendor advisories and patch information. Affected products include: Kaltura Kaltura Server.