CVE-2021-21399

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
13/04/2021
Last modified:
21/10/2022

Description

Ampache is a web based audio/video streaming application and file manager. Versions prior to 4.4.1 allow unauthenticated access to Ampache using the subsonic API. To successfully make the attack you must use a username that is not part of the site to bypass the auth checks. For more details and workaround guidance see the referenced GitHub security advisory.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ampache:ampache:*:*:*:*:*:*:*:* 4.4.1 (excluding)