CVE-2024-29882 is a Cross-Site Scripting (XSS) vulnerability affecting SRS (Simple Realtime Server) versions prior to 5.0.210 and 6.0.121. This medium-severity vulnerability (CVSS 6.1) allows unauthenticated attackers to inject malicious JavaScript payloads via an unfiltered callback function in the /api/v1/vhosts/vid-<id> endpoint, potentially leading to information disclosure and integrity compromise. While not currently listed in CISA's KEV catalog, exploit intelligence indicates the availability of Nuclei templates for detection. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.0.210CPE matchmatch criteria | cpe:2.3:a:ossrs:simple_realtime_server:*:*:*:*:*:*:*:* | ||
>= 6.0.0, < 6.0.121CPE matchmatch criteria | cpe:2.3:a:ossrs:simple_realtime_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.