rudloff/alltube
HTML GUI for youtube-dl
Activity
- Latest release
- 3y ago
- Total releases
- 57
- Cadence
- ~40 days
- Last 12 months
- 0
Reach
- Stars
- —
Details
- License
- unknown
- First release
- Aug 01, 2015
| Version | Released | |
|---|---|---|
3.2.0-alpha
pre
deprecated
|
3.2.0-alpha
pre
deprecated
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
3.1.1
patch
|
3.1.1
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
3.1.0
minor
| ||
3.0.3
patch
|
3.0.3
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
3.0.2
patch
1 CVE
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
3.0.1
patch
2 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev |
3.0.1
patch
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
3.0.0
major
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
3.0.0-beta5
pre
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
3.0.0-beta5
pre
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
3.0.0-beta4
pre
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
3.0.0-beta4
pre
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
3.0.0-beta3
pre
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
3.0.0-beta3
pre
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
3.0.0-beta2
pre
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
3.0.0-beta2
pre
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
3.0.0-beta
pre
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
3.0.0-beta
pre
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
2.3.0
minor
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.3.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
2.2.1
patch
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.2.1
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
2.2.0
minor
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
2.1.0
minor
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.1.0
minor
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
2.0.5
patch
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.0.5
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
2.0.4
patch
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
2.0.3
patch
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
2.0.2
patch
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
2.0.1
patch
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
2.0.0
major
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.2.5
patch
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
1.2.5
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
1.2.4
patch
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
1.2.4
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
1.2.3
patch
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.2.2
patch
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.2.1
patch
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.2.0
minor
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.1.3
patch
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.1.2
patch
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.1.1
patch
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.1.0
minor
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.0.0
major
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.11.0
minor
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.10.2
patch
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.10.2
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
0.10.1
patch
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.10.0
minor
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.10.0
minor
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
0.9.0
minor
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.9.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.8.1-beta
pre
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.8.1-beta
pre
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.8.0
minor
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.7.2-beta2
pre
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.7.2-beta
pre
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.7.1
patch
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.7.0
minor
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.6.0
minor
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.5.2
patch
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.5.2
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.5.1
patch
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.5.1
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.5.0
minor
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.5.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.4.5
patch
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.4.4
patch
3 CVEs
CVE-2022-24739
GHSA-75p7-527p-w8wp
Mar 09, 2022
Server-Side Request Forgery and Open Redirect in AllTube Download
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
ImpactOn releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the Patches3.0.3 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) The fix requires applying a patch to youtube-dl to disable its generic extractor. If you are using the version of youtube-dl bundled with 3.0.3, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 41 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
3.0.2
Fixed in
3.0.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-0768
GHSA-r5hc-wm3g-hjw6
Mar 01, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactReleases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname. Patches3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable. References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 40 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
3.0.1
Fixed in
3.0.2
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2022-0692
GHSA-jmhf-9fj8-88gh
Feb 23, 2022
Open Redirect in AllTube
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactReleases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. Patches3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) References
Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
+ 39 more Show less
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2-beta
0.7.2-beta2
0.8.0
0.8.1-beta
0.9.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.2.0
2.2.1
2.3.0
3.0.0
3.0.0-beta
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-beta5
Fixed in
3.0.1
References
Updated Feb 16, 2024 · Source: OSV.dev |