Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS1wbWNyLTJyaHAtMzZocs0mRw
SQL injection in github.com/navidrome/navidrome
model/criteria/criteria.go in Navidrome before 0.47.5 is vulnerable to SQL injection attacks when processing crafted Smart Playlists. An authenticated user could abuse this to extract arbitrary data from the database, including the user table (which contains sensitive information such as the users' encrypted passwords).
Permalink: https://github.com/advisories/GHSA-pmcr-2rhp-36hrJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1wbWNyLTJyaHAtMzZocs0mRw
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: almost 3 years ago
Updated: almost 2 years ago
Identifiers: GHSA-pmcr-2rhp-36hr, CVE-2022-23857
References:
- https://nvd.nist.gov/vuln/detail/CVE-2022-23857
- https://github.com/navidrome/navidrome/commit/9e79b5cbf2a48c1e4344df00fea4ed3844ea965d
- https://github.com/navidrome/navidrome/releases/tag/v0.47.5
- https://github.com/advisories/GHSA-pmcr-2rhp-36hr
Blast Radius: 0.0
Affected Packages
go:github.com/navidrome/navidrome
Dependent packages: 0Dependent repositories: 1
Downloads:
Affected Version Ranges: < 0.47.5
Fixed in: 0.47.5
All affected versions: 0.3.0, 0.3.1, 0.3.2, 0.4.0, 0.4.1, 0.4.2, 0.5.0, 0.6.0, 0.6.1, 0.6.2, 0.7.0, 0.7.1, 0.7.2, 0.7.3, 0.8.0, 0.8.1, 0.8.2, 0.8.3, 0.8.4, 0.9.0, 0.9.1, 0.9.2, 0.9.3, 0.10.0, 0.11.0, 0.11.1, 0.12.0, 0.13.0, 0.14.0, 0.14.1, 0.14.2, 0.14.3, 0.14.4, 0.14.5, 0.15.0, 0.16.0, 0.16.1, 0.17.0, 0.18.0, 0.19.0, 0.20.0, 0.21.0, 0.22.0, 0.23.0, 0.23.1, 0.24.0, 0.25.0, 0.26.0, 0.26.1, 0.27.0, 0.28.0, 0.29.0, 0.30.0, 0.30.1, 0.31.0, 0.32.0, 0.33.0, 0.34.0, 0.34.1, 0.35.0, 0.35.1, 0.36.0, 0.36.1, 0.37.0, 0.38.0, 0.39.0, 0.40.0, 0.41.0, 0.41.1, 0.42.0, 0.42.1, 0.43.0, 0.44.0, 0.44.1, 0.45.0, 0.45.1, 0.46.0, 0.47.0
All unaffected versions: 0.47.5, 0.48.0, 0.49.0, 0.49.1, 0.49.2, 0.49.3, 0.50.0, 0.50.1, 0.50.2, 0.51.0, 0.51.1, 0.52.0, 0.52.5, 0.53.0, 0.53.1, 0.53.2, 0.53.3