PT-2024-30665 · Unknown · Audiobookshelf
Dominator98
+1
·
Published
2024-09-02
·
Updated
2024-09-13
·
CVE-2024-43797
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Audiobookshelf versions prior to 2.13.0
Description
Audiobookshelf is a self-hosted audiobook and podcast server where a non-admin user is not allowed to create libraries or access only the ones they have permission to. However, the
LibraryController is missing the check for admin user, allowing a path traversal issue. This enables non-admin users to write to any directory in the system, which can be restricted to only admin permissions, making it a Role-Based Access Control (RBAC) issue. The issue has been addressed in release version 2.13.0.Recommendations
For versions prior to 2.13.0, upgrade to version 2.13.0 to resolve the issue. As a temporary workaround, consider restricting access to the
LibraryController to minimize the risk of exploitation. There are no known workarounds for this vulnerability other than upgrading to the fixed version.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Audiobookshelf