CVE-2023-47624

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
13/12/2023
Last modified:
19/12/2023

Description

Audiobookshelf is a self-hosted audiobook and podcast server. In versions 2.4.3 and prior, any user (regardless of their permissions) may be able to read files from the local file system due to a path traversal in the `/hls` endpoint. This issue may lead to Information Disclosure. As of time of publication, no patches are available.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:audiobookshelf:audiobookshelf:*:*:*:*:*:*:*:* 2.4.3 (including)