CVE-2024-56362

Navidrome is an open source web-based music collection server and streamer. Navidrome stores the JWT secret in plaintext in the navidrome.db database file under the property table. This practice introduces a security risk because anyone with access to the database file can retrieve the secret. This vulnerability is fixed in 0.54.1.
Configurations

No configuration.

History

23 Dec 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-23 18:15

Updated : 2024-12-23 18:15


NVD link : CVE-2024-56362

Mitre link : CVE-2024-56362

CVE.ORG link : CVE-2024-56362


JSON object : View

Products Affected

No product.

CWE
CWE-312

Cleartext Storage of Sensitive Information