Sunshine is a self-hosted game stream host for Moonlight. Starting in version 0.10.0 and prior to version 0.23.0, after unpairing all devices in the web UI interface and then pairing only one device, all of the previously devices will be temporarily paired. Version 0.23.0 contains a patch for the issue. As a workaround, restarting Sunshine after unpairing all devices prevents the vulnerability.
References
Link | Resource |
---|---|
https://github.com/LizardByte/Sunshine/commit/b7aa8119f1471844dccdf73a8b6f7efc9baddb5e | Patch |
https://github.com/LizardByte/Sunshine/issues/2305 | Exploit Issue Tracking |
https://github.com/LizardByte/Sunshine/pull/2365 | Issue Tracking Patch |
https://github.com/LizardByte/Sunshine/security/advisories/GHSA-v8gw-jw28-v55m | Vendor Advisory |
https://github.com/LizardByte/Sunshine/commit/b7aa8119f1471844dccdf73a8b6f7efc9baddb5e | Patch |
https://github.com/LizardByte/Sunshine/issues/2305 | Exploit Issue Tracking |
https://github.com/LizardByte/Sunshine/pull/2365 | Issue Tracking Patch |
https://github.com/LizardByte/Sunshine/security/advisories/GHSA-v8gw-jw28-v55m | Vendor Advisory |
Configurations
History
11 Sep 2025, 21:41
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:lizardbyte:sunshine:*:*:*:*:*:*:*:* | |
First Time |
Lizardbyte
Lizardbyte sunshine |
|
References | () https://github.com/LizardByte/Sunshine/commit/b7aa8119f1471844dccdf73a8b6f7efc9baddb5e - Patch | |
References | () https://github.com/LizardByte/Sunshine/issues/2305 - Exploit, Issue Tracking | |
References | () https://github.com/LizardByte/Sunshine/pull/2365 - Issue Tracking, Patch | |
References | () https://github.com/LizardByte/Sunshine/security/advisories/GHSA-v8gw-jw28-v55m - Vendor Advisory |
Information
Published : 2024-04-08 15:15
Updated : 2025-09-11 21:41
NVD link : CVE-2024-31221
Mitre link : CVE-2024-31221
CVE.ORG link : CVE-2024-31221
JSON object : View
Products Affected
lizardbyte
- sunshine
CWE
CWE-384
Session Fixation