CVE-2024-56362
—CVSS 3.1
5.5 medium
EPSS
<1%p5
Published
()
Modified
Description
Navidrome is an open source web-based music collection server and streamer. Navidrome stores the JWT secret in plaintext in the navidrome.db database file under the property table. This practice introduces a security risk because anyone with access to the database file can retrieve the secret. This vulnerability is fixed in 0.54.1.
- Vendors
- navidrome
- Products
- navidrome
- Weakness
- CWE-312
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.