PT-2024-25010 · Navidrome · Navidrome

Viliald

·

Published

2024-05-01

·

Updated

2024-09-20

·

CVE-2024-32963

CVSS v3.1

4.2

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Navidrome versions prior to 0.52.0
Description Navidrome is an open source web-based music collection server and streamer. The issue is a parameter tampering vulnerability where an attacker can manipulate parameter values in the HTTP requests, allowing them to impersonate another user. This can be done by changing the parameter values in the body, and the attacker must be able to intercept HTTP traffic for this attack. Each known user is impacted, and an attacker can obtain the ownerId from shared playlist information, meaning every user who has shared a playlist is also impacted, as they can be impersonated.
Recommendations For Navidrome versions prior to 0.52.0, upgrade to version 0.52.0 to address the issue. As a temporary workaround, consider restricting access to shared playlists and limiting the ability to intercept HTTP traffic. Avoid using shared playlist information to minimize the risk of exploitation. There are no known workarounds for this vulnerability other than upgrading to the fixed version.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-32963
GHSA-4JRX-5W4H-3GPM
GO-2024-2803

Affected Products

Navidrome