gist.github.com
https://gist.github.com/nyxfqq/d192af10b53a363e2d9e430068333e04 CVE-2024-41259
Navidrome uses MD5 hashing algorithm
Description
Use of insecure hashing algorithm in the Gravatar's service in Navidrome v0.52.3 allows attackers to manipulate a user's account information.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 2, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
navidromeBrowse navidrome / navidromeDefault status: unknown | CVE List | v0.52.3 | affected |
github.com/navidrome/navidromeBrowse Go / github.com/navidrome/navidrome | GitHub Advisory | Through 0.52.3 | affected |
References
4github.com
https://github.com/navidrome/navidrome nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-41259 pkg.go.dev
https://pkg.go.dev/vuln/GO-2024-3029