Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
🛡️
Not in CISA KEV
MEDIUM severity

CVE-2023-4714 — Playtube

MEDIUM

CVE-2023-4714 is a medium-severity (CVSS 4.3) Information Exposure vulnerability in playtube playtube. No vendor fix is recorded yet; mitigation options are listed below.

A vulnerability was found in PlayTube 3.0.1 and classified as problematic. This issue affects some unknown processing of the component Redirect Handler. The manipulation leads to information…

Published
Updated
Affected
1 product
Patched
See advisory
Exploits
None indexed
Exploitation data as of Oct 9, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

Exploitation Status

Proof-of-concept exploit code exists

  • CISA’s SSVC triage found public proof-of-concept exploit code for this CVE, though no confirmed active exploitation.
  • CISA assesses this as automatable — exploitation doesn’t require manual, per-target effort, which raises the odds of mass scanning and opportunistic attacks.

Exploitation and automatability from CISA’s SSVC triage for CVE-2023-4714.

EPSS Exploitation Probability

via FIRST.org ↗
5.5%probability of exploitation in next 30 days
Lower Risk0.00%
Lower risk than most CVEs93th percentile — riskier than 93% of all scored CVEsHighest risk
0.00%33.3%66.7%100.0%90.0%5.5%5.5%May 26Oct 26Oct 26

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

How urgent is this, really

CVE-2023-4714 by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.

Where this sits among everything scored

Of 385,386 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.

Description

A vulnerability was found in PlayTube 3.0.1 and classified as problematic. This issue affects some unknown processing of the component Redirect Handler. The manipulation leads to information disclosure. The attack may be initiated remotely. The identifier VDB-238577 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Affected Products

1 product · 1 configurations
Application
playtubeplaytube
1 version
3.0.1

Detection & mitigation playbook

Vendor / appliance
  1. Detect

    Inventory every playtube playtube deployment and check each version against the affected-products list above.

  2. Remediation status

    No patch has shipped for CVE-2023-4714 yet — track the playtube playtube advisory for a fixed release and apply the workarounds below in the meantime.

  3. Mitigate without a patch

    Assume what was exposed is already known: rotate any credential, token or key that the affected component could return, restrict the endpoint to callers that genuinely need it, and strip sensitive fields from responses and error output at the boundary rather than relying on the client not to read them. Alongside that, restrict the management interface to trusted networks and apply the vendor's recommended configuration mitigations.

How to detect CVE-2023-4714

A community-maintained Nuclei template exists for this CVE. You can scan for it directly:

nuclei -id cve-2023-4714 -u https://target
Template
PlayTube 3.0.1 - Information Disclosure
Severity
high
Impact
An attacker can exploit this vulnerability to gain access to sensitive information.
Remediation
Apply the latest security patches and updates from the vendor to address this vulnerability.

Template by ProjectDiscovery nuclei-templates (Farish), MIT licensed. View the full template. Scan only systems you are authorised to test.

Frequently Asked Questions

A vulnerability was found in PlayTube 3.0.1 and classified as problematic. This issue affects some unknown processing of the component Redirect Handler. The manipulation leads to information disclosure. The attack may be initiated remotely. The identifier VDB-238577 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
O3 Security · Runtime Protection

Is CVE-2023-4714 being exploited in your environment?

Detect and block the exploit chain at execution, on systems you cannot patch yet.

CVE-2023-4714: Playtube Info Disclosure (Medium 4.3)