Severity 9.1 - Authenticated user container escape.

The latest release fixes this.

See details here

all 10 comments

sorted by: hot top controversial new old
[–] 16 points 7 months ago (8 children)

This is why you don't expose services to the Internet, especially with weak or no authentication.

  • source
  • hideshow 8 child comments
  • [–] 7 points 7 months ago (7 children)

    I'm not sure why anyone would want to expose Frigate of all things to the open internet.

  • source
  • parent
  • hideshow 7 child comments
  • [–] 6 points 7 months ago (6 children)

    So they could view their cameras while they're away?

  • source
  • parent
  • hideshow 6 child comments
  • [–] 2 points 7 months ago (3 children)

    There are far better, more secure ways to do this. You could use a reverse proxy. You could use tailscale. You could use wireguard.

    The last thing you should do is open Frigate's port to the net.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 2 points 7 months ago (2 children)

    Just answering the question you asked.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 7 months ago* (1 child)

    I know, but it seemed like there was confusion about my intended point, which is that you should never expose it to the open internet. It wasn't a question I really intended to be answered since I know that was their intention. My confusion is why do that when there are secure alternatives, some of which are easier than opening a port.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 8 points 7 months ago*

    "This vulnerability is only exploitable by an administrator or users who have exposed their Frigate install to the open internet with no authentication which allows anyone full administrative control." High, but not critical

  • source