QID 996395
Date Published: 2023-12-21
QID 996395: GO (Go) Security Update for github.com/navidrome/navidrome (GHSA-wq59-4q6r-635r)
A security vulnerability has been identified in navidrome's subsonic endpoint, allowing for authentication bypass. This exploit enables unauthorized access to any known account by utilizing a JSON Web Token (JWT) signed with the key "not so secret".
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-wq59-4q6r-635r for updates and patch information.
Vendor References
- GHSA-wq59-4q6r-635r -
github.com/advisories/GHSA-wq59-4q6r-635r
CVEs related to QID 996395
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-wq59-4q6r-635r | github.com/navidrome/navidrome |
|