
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-10574 is a vulnerability discovered in the Janus Gateway software, specifically related to a typo in the querylogger_parameters function. The issue was identified and disclosed in March 2020, affecting the Janus WebRTC server/gateway. The vulnerability was caused by a copy/paste error in the JSON validation of the 'query_logger' Admin API request (Janus PR).
The vulnerability stems from a typo in the JSON validation of the 'query_logger' Admin API request that could lead to attempting to use a non-existent string. This was identified as a copy-paste error that occurred when duplicating the existing 'query_handler' functionality to support loggers (Janus PR).
The vulnerability could potentially cause the application to attempt accessing a non-existent string, which might lead to undefined behavior in the Janus Gateway server (Janus PR).
The vulnerability could be triggered through the Admin API by sending specifically crafted requests to the query_logger endpoint (Janus PR).
The issue was fixed by correcting the typo in the querylogger_parameters validation. The fix was implemented and merged into the master branch of the Janus Gateway project (Janus PR).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."