GHSA-mwjc-5j4x-r686: AVideo has an unauthenticated decrypt oracle leaking any ciphertext
The API plugin exposes a decryptString action without any authentication. Anyone can submit ciphertext and receive plaintext. Ciphertext is issued publicly (e.g., view/url2Embed.json.php), so any user can recover protected tokens/metadata. Severity: High.
References
Code Behaviors & Features
Detect and mitigate GHSA-mwjc-5j4x-r686 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →