← volver
CVE-2023-51665

Audiobookshelf vulnerable to Blind SSRF in `Auth.js`

CVSS 4.3 MEDIUMEPSS 0.3%CWE-918
Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.7.0, Audiobookshelf is vulnerable to unauthenticated blind server-side request (SSRF) vulnerability in Auth.js. This vulnerability has been addressed in version 2.7.0. There are no known workarounds for this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Productos afectados
advplyr · audiobookshelf

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →