{"id":"CVE-2022-24739","aliases":["GHSA-75p7-527p-w8wp"],"url":"https://o3.security/vulnerability/CVE-2022-24739","summary":"Server-Side Request Forgery (SSRF) and URL Redirection to Untrusted Site ('Open Redirect') in alltube","details":"alltube is an html front end for youtube-dl. On releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact the SSRF attack is only possible when the `stream` option is enabled in the configuration. (This option is disabled by default.) 3.0.3 contains a fix for this vulnerability.","published":"2022-03-08T21:40:10Z","modified":"2026-08-12T03:51:08.215949818Z","cvss":{"score":7.3,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"},"epss":{"score":0.00912,"percentile":0.56878,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"rudloff/alltube","fixedVersion":"3.0.3"}],"fix":{"url":"https://github.com/Rudloff/alltube/commit/3a4f09dda0a466662a4e52cde674749e0c668e8d","label":"Rudloff/alltube@3a4f09d"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/24xxx/CVE-2022-24739.json"},{"type":"ADVISORY","url":"https://github.com/Rudloff/alltube/security/advisories/GHSA-75p7-527p-w8wp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-24739"},{"type":"FIX","url":"https://github.com/Rudloff/alltube/commit/3a4f09dda0a466662a4e52cde674749e0c668e8d"},{"type":"FIX","url":"https://github.com/Rudloff/alltube/commit/8913f27716400dabf4906a5ad690a5238f73496a"},{"type":"FIX","url":"https://github.com/Rudloff/alltube/commit/bc14b6e45c766c05757fb607ef8d444cbbfba71a"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:08.215949818Z"}}