CVE-2024-56362 affects Navidrome, an open-source music server, by storing the JWT secret in plaintext within its database file. This allows any attacker with local access to the database to retrieve the secret, posing a medium severity risk (CVSS 5.5) due to potential compromise of user authentication. While the vulnerability has a high confidentiality impact, it requires local access and has no known public exploits, Metasploit modules, or significant community discussion. A fix is available in Navidrome version 0.54.1.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.54.1CPE matchmatch criteria | cpe:2.3:a:navidrome:navidrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.