VDB
Sign up
HIGH7.3

GHSA-75p7-527p-w8wp

Server-Side Request Forgery and Open Redirect in AllTube Download

Quick fix

GHSA-75p7-527p-w8wp — rudloff/alltube: upgrade to the fixed version with the command below.

composer require rudloff/alltube:^3.0.3

Details

### Impact

On releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured).

The impact is mitigated by the fact the SSRF attack is only possible when the `stream` option is enabled in the configuration. (This option is disabled by default.)

### Patches

3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.)

The fix requires applying [a patch](https://github.com/Rudloff/alltube/blob/3d092891044f2685ed66c73c870a021bee319c37/patches/youtube-dl-disable-generic.diff) to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl **you might still be vulnerable**.

### References

* https://github.com/Rudloff/alltube/commit/8913f27716400dabf4906a5ad690a5238f73496a * https://github.com/ytdl-org/youtube-dl/issues/30691

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/rudloff/alltube
Introduced in: 0Fixed in: 3.0.3
Fixcomposer require rudloff/alltube:^3.0.3

References