Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xwx7-p63r-2rj8

Опубликовано: 23 дек. 2024
Источник: github
Github: Прошло ревью
CVSS3: 7.1

Описание

Navidrome Stores JWT Secret in Plaintext in navidrome.db

Navidrome stores the JWT secret in plaintext in the navidrome.db database file under the property table. This practice introduces a security risk because anyone with access to the database file can retrieve the secret. The JWT secret is critical for the authentication and authorization system. If exposed, an attacker could:

  • Forge valid tokens to impersonate users, including administrative accounts.
  • Gain unauthorized access to sensitive data or perform privileged actions. This vulnerability has been tested on the latest version of Navidrome and poses a significant risk in environments where the database file is not adequately secured.

image

Пакеты

Наименование

github.com/navidrome/navidrome

go
Затронутые версииВерсия исправления

<= 0.53.3

0.54.1

EPSS

Процентиль: 3%
0.00018
Низкий

7.1 High

CVSS3

Дефекты

CWE-312

Связанные уязвимости

CVSS3: 7.1
nvd
8 месяцев назад

Navidrome is an open source web-based music collection server and streamer. Navidrome stores the JWT secret in plaintext in the navidrome.db database file under the property table. This practice introduces a security risk because anyone with access to the database file can retrieve the secret. This vulnerability is fixed in 0.54.1.

suse-cvrf
7 месяцев назад

Security update for govulncheck-vulndb

EPSS

Процентиль: 3%
0.00018
Низкий

7.1 High

CVSS3

Дефекты

CWE-312