Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-21399

Опубликовано: 13 апр. 2021
Источник: nvd
CVSS3: 9.1
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

Ampache is a web based audio/video streaming application and file manager. Versions prior to 4.4.1 allow unauthenticated access to Ampache using the subsonic API. To successfully make the attack you must use a username that is not part of the site to bypass the auth checks. For more details and workaround guidance see the referenced GitHub security advisory.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ampache:ampache:*:*:*:*:*:*:*:*
Версия до 4.4.1 (исключая)

EPSS

Процентиль: 58%
0.0037
Низкий

9.1 Critical

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-284
CWE-287

Связанные уязвимости

CVSS3: 9.1
ubuntu
почти 5 лет назад

Ampache is a web based audio/video streaming application and file manager. Versions prior to 4.4.1 allow unauthenticated access to Ampache using the subsonic API. To successfully make the attack you must use a username that is not part of the site to bypass the auth checks. For more details and workaround guidance see the referenced GitHub security advisory.

CVSS3: 9.1
debian
почти 5 лет назад

Ampache is a web based audio/video streaming application and file mana ...

EPSS

Процентиль: 58%
0.0037
Низкий

9.1 Critical

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-284
CWE-287