CVE-2023-46121
CVSS 3.1 Score 3.7 of 10 (low)
Details
Summary
CVE-2023-46121 is a vulnerability in yt-dlp, a youtube-dl fork with additional features and fixes. The Generic Extractor in yt-dlp allows an attacker to set an arbitrary proxy for a request to any URL, potentially enabling them to perform a Man-in-the-Middle (MITM) attack on the request made from yt-dlp's HTTP session. This could lead to cookie exfiltration in certain scenarios. The issue has been addressed in version 2023.11.14 by removing the ability to smuggle `http_headers` to the Generic Extractor and other extractors using the same pattern. Users are advised to upgrade their version of yt-dlp, and if unable to do so, they should disable the Generic Extractor or only pass trusted sites with trusted content and exercise caution when using `--no-check-certificate`. The vulnerability has a base severity rating of LOW, with a CVSS v3.1 base score of 3.7 out of 10.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Advisories, Assessments, and Mitigations
Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future
- Gain complete coverage of your cyber, third party, and physical attack surface
- Proactively mitigate threats before they turn into costly attacks
- Make fast, effective, data-driven decisions