CVE-2023-47619
Audiobookshelf Server-Side Request Forgery and Arbitrary File Read Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Audiobookshelf is a self-hosted audiobook and podcast server. In versions 2.4.3 and prior, users with the update permission are able to read arbitrary files, delete arbitrary files and send a GET request to arbitrary URLs and read the response. This issue may lead to Information Disclosure. As of time of publication, no patches are available.
Audiobookshelf es un servidor de podcasts y audiolibros autohospedado. En las versiones 2.4.3 y anteriores, los usuarios con permiso de actualización pueden leer archivos arbitrarios, eliminar archivos arbitrarios y enviar una solicitud GET a URL arbitrarias y leer la respuesta. Este problema puede dar lugar a la divulgación de información. Al momento de la publicación, no hay parches disponibles.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-11-07 CVE Reserved
- 2023-12-13 CVE Published
- 2024-08-02 CVE Updated
- 2024-08-02 First Exploit
- 2024-12-19 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-918: Server-Side Request Forgery (SSRF)
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://github.com/advplyr/audiobookshelf/blob/d7b2476473ef1934eedec41425837cddf2d4b13e/server/controllers/AuthorController.js#L66 | Product |
URL | Date | SRC |
---|---|---|
https://securitylab.github.com/advisories/GHSL-2023-203_GHSL-2023-204_audiobookshelf | 2024-08-02 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Audiobookshelf Search vendor "Audiobookshelf" | Audiobookshelf Search vendor "Audiobookshelf" for product "Audiobookshelf" | <= 2.4.3 Search vendor "Audiobookshelf" for product "Audiobookshelf" and version " <= 2.4.3" | - |
Affected
|