CVE-2024-56362
Navidrome Stores JWT Secret in Plaintext in navidrome.db
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Navidrome is an open source web-based music collection server and streamer. Navidrome stores the JWT secret in plaintext in the navidrome.db database file under the property table. This practice introduces a security risk because anyone with access to the database file can retrieve the secret. This vulnerability is fixed in 0.54.1.
Navidrome es un servidor y transmisor de colección de música basado en web de código abierto. Navidrome almacena el secreto JWT en texto plano en el archivo de base de datos navidrome.db en la tabla de propiedades. Esta práctica introduce un riesgo de seguridad porque cualquiera que tenga acceso al archivo de la base de datos puede recuperar el secreto. Esta vulnerabilidad se solucionó en 0.54.1.
These are all security issues fixed in the govulncheck-vulndb-0.0.20250108T191942-1.1 package on the GA media of openSUSE Tumbleweed.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2024-12-20 CVE Reserved
- 2024-12-23 CVE Published
- 2024-12-24 CVE Updated
- 2025-06-02 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-312: Cleartext Storage of Sensitive Information
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://github.com/navidrome/navidrome/commit/7f030b0859653593fd2ac0df69f4a313f9caf9ff | X_refsource_misc | |
https://github.com/navidrome/navidrome/commit/9cbdb20a318a49daf95888b1fd207d4d729b55f1 | X_refsource_misc | |
https://github.com/navidrome/navidrome/security/advisories/GHSA-xwx7-p63r-2rj8 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Navidrome Search vendor "Navidrome" | Navidrome Search vendor "Navidrome" for product "Navidrome" | < 0.54.1 Search vendor "Navidrome" for product "Navidrome" and version " < 0.54.1" | en |
Affected
|