blob: 658fbe9e19d2b1bfe5ee077649424916d0d9b915 [file] [log] [blame]
id: GO-2023-2414
modules:
- module: github.com/navidrome/navidrome
versions:
- fixed: 0.50.2
vulnerable_at: 0.50.1
summary: Authentication bypass vulnerability in navidrome's subsonic endpoint in github.com/navidrome/navidrome
cves:
- CVE-2023-51442
ghsas:
- GHSA-wq59-4q6r-635r
references:
- advisory: https://github.com/navidrome/navidrome/security/advisories/GHSA-wq59-4q6r-635r
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2023-51442
- fix: https://github.com/navidrome/navidrome/commit/1132abb0135d1ecaebc41ed97a1e908a4ae02f7c
source:
id: GHSA-wq59-4q6r-635r
created: 2024-08-20T12:22:33.088629-04:00
review_status: UNREVIEWED
unexcluded: EFFECTIVELY_PRIVATE