CyberRota Analysis
AI-GeneratedThe vulnerability affects the Frigate network video recorder, specifically in version 0.17.1, where the GET /api/logs/{service} endpoint permits any authenticated user, including those with viewer roles, to access sensitive logs. This exposure can lead to the disclosure of auto-generated admin passwords and camera credentials, facilitating privilege escalation from viewer to admin. Organizations using this version of Frigate should prioritize immediate remediation to mitigate the risk of unauthorized access and potential system compromise.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Frigate is an open source network video recorder. In version 0.17.1, the GET /api/logs/{service} endpoint allows any authenticated user including the viewer role to download Frigate and nginx logs, exposing auto-generated admin passwords and camera credentials logged in request query strings and enabling viewer-to-admin privilege escalation. A fixed release has not been identified.