Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code
Summary
Two unpatched vulnerabilities have been disclosed in Kaltura's HTML5 video player library by CERT/CC. These flaws allow remote, unauthenticated attackers to read arbitrary files from a server and execute code.
IFF Assessment
FOE
These vulnerabilities allow unauthenticated attackers to read files and execute code on a server, posing a significant risk to data confidentiality and system integrity.
Severity
7.5
High
Defender Context
Defenders should be aware of these vulnerabilities in Kaltura's mwEmbed library, as unpatched systems are at high risk of compromise. Prioritizing patching or implementing mitigating controls is crucial to prevent unauthorized file access and remote code execution.