CVE-2024-31221

MEDIUM

Sunshine <0.23.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

Sunshine is a self-hosted game stream host for Moonlight. Starting in version 0.10.0 and prior to version 0.23.0, after unpairing all devices in the web UI interface and then pairing only one device, all of the previously devices will be temporarily paired. Version 0.23.0 contains a patch for the issue. As a workaround, restarting Sunshine after unpairing all devices prevents the vulnerability.

Scores

CVSS v3 5.9
EPSS 0.0009
EPSS Percentile 24.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-384
Status published
Products (1)
lizardbyte/sunshine 0.10.0 - 0.23.0
Published Apr 08, 2024
Tracked Since Feb 18, 2026