PT-2021-14476 · Ampache · Ampache

Lachlan-00

·

Published

2021-04-13

·

Updated

2022-10-21

·

CVE-2021-21399

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Ampache versions prior to 4.4.1
Description The issue allows unauthenticated access to Ampache using the subsonic API. To exploit this, an attacker must use a username that is not part of the site to bypass the auth checks.
Recommendations For versions prior to 4.4.1, update to version 4.4.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the subsonic API until a patch is applied. Avoid using unknown or unverified username values in the subsonic API to minimize the risk of exploitation.

Exploit

Fix

Improper Authentication

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2021-21399
GHSA-P9PM-J95J-5MJF

Affected Products

Ampache