CVE-2024-56362

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Dec 23, 2024
CWE ID 312

Summary

CVE-2024-56362: Navidrome, an open-source music collection server and streamer, contains a security vulnerability that permits unauthorized access. The issue lies in the storage of the JWT secret in plaintext within the navidrome.db database file, specifically in the property table. This lack of encryption introduces a significant risk, as anyone who gains access to the database file can easily retrieve the secret. Navidrome has addressed this issue with the release of version 0.54.1.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share