Web-Based Music Collection Server Vulnerability in Navidrome
CVE-2024-56362
What is CVE-2024-56362?
Navidrome, a popular open source web-based music collection server, has a security vulnerability stemming from the insecure handling of JSON Web Token (JWT) secrets. The JWT secret is stored in plaintext within the navidrome.db database file, specifically under the property table. This creates a potential security risk as anyone with access to the database can easily retrieve the JWT secret, compromising the integrity and confidentiality of the application. To mitigate this issue, it is strongly recommended to upgrade to version 0.54.1 or later, where this vulnerability has been addressed.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
navidrome < 0.54.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
