moonfire-nvr/server
Scott Lamb 4c9aa93fdf check WebSocket origin
This fixes a real cross-site WebSocket hijacking (CSWSH) vulnerability.
If the attacker knows the URL of an NVR installation this user is
authenticated to and the UUID of a camera, and can trick the user into
visiting their webpage, they can grab the live stream. At least there's
some entropy in the camera UUID, but it was never intended to be a
secret.
2022-03-22 14:51:12 -07:00
..
base fix #187 via a dependency upgrade 2022-03-08 11:24:44 -08:00
db prepare v0.7.2 2022-03-16 18:31:12 -07:00
src check WebSocket origin 2022-03-22 14:51:12 -07:00
Cargo.lock drop ffmpeg support 2022-03-18 13:22:47 -07:00
Cargo.toml drop ffmpeg support 2022-03-18 13:22:47 -07:00