github.com
https://github.com/navidrome/navidrome CVE-2022-23857
MEDIUM
SQL injection in github.com/navidrome/navidrome
Record summary
CVE-2022-23857 has a selected CVSS score of 6.5 (medium).
Description
model/criteria/criteria.go in Navidrome before 0.47.5 is vulnerable to SQL injection attacks when processing crafted Smart Playlists. An authenticated user could abuse this to extract arbitrary data from the database, including the user table (which contains sensitive information such as the users' encrypted passwords).
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
github.com/navidrome/navidromeBrowse Go / github.com/navidrome/navidrome | GitHub Advisory | Before 0.47.5 · Fixed in 0.47.5 | affected |
References
4github.com
https://github.com/navidrome/navidrome/commit/9e79b5cbf2a48c1e4344df00fea4ed3844ea965d github.com
https://github.com/navidrome/navidrome/releases/tag/v0.47.5 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-23857