OSV 1.4.0 · github-reviewed · 修改于 2022-01-26 05:03
发布时间
2022-01-28 00:23
GitHub 审查时间
2022-01-26 05:03
NVD 发布时间
2022-01-24 10:15
源文件
advisories/github-reviewed/2022/01/GHSA-pmcr-2rhp-36hr/GHSA-pmcr-2rhp-36hr.json
model/criteria/criteria.go in Navidrome before 0.47.5 is vulnerable to SQL injection attacks when processing crafted Smart Playlists. An authenticated user could abuse this to extract arbitrary data from the database, including the user table (which contains sensitive information such as the users' encrypted passwords).