25

This is an important security fix. Please update ASAP. A proper CVE advisory will be published soon and will be linked here.

you are viewing a single comment's thread
view the rest of the comments
[-] Deebster@programming.dev 3 points 2 years ago* (last edited 2 years ago)

This seems quite serious, I'll definitely be reading the CVE once it's published. Luckily, I noticed the github notification of the release after only a couple of hours.

edit: I read the advisory and it wasn't too bad in terms of attacker access:

Impact
An attacker can use any non-existent username to bypass the authentication system and gain access to various read-only data in Navidrome, such as user playlists. However, any attempt to modify data fails due to insufficient permissions, limiting the impact to unauthorized viewing of information.

this post was submitted on 21 Feb 2025
25 points (100.0% liked)

Navidrome Music Server (Unofficial)

545 readers
1 users here now

Navidrome is a free, open source web-based music collection server and streamer. It gives you freedom to listen to your music collection from any browser or mobile device. https://www.navidrome.org/

This is an unofficial community. However, we adhear to the official Code Of Conduct set by the Navidrome project.

founded 3 years ago
MODERATORS