PT-2024-22326 · Unknown · Yourspotify

Ragingcactus

·

Published

2024-03-13

·

Updated

2024-03-15

·

CVE-2024-28192

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions YourSpotify versions prior to 1.8.0
Description The issue concerns a NoSQL injection vulnerability in the public access token processing logic. This allows attackers to bypass the public token authentication mechanism without user interaction or prerequisite knowledge.
Recommendations For versions prior to 1.8.0, upgrade to version 1.8.0 to resolve the issue. As a temporary workaround, consider restricting access to the public access token processing logic until the upgrade is applied. Avoid using the public access token feature in affected versions until the issue is resolved.

Exploit

Fix

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2024-28192
GHSA-C8WF-WCJC-2PVM

Affected Products

Yourspotify