An issue was discovered in badaix Snapcast version 0.27.0, allows remote attackers to execute arbitrary code and gain sensitive information via crafted request in JSON-RPC-API.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
http://snapcast.com | |
https://oxnan.com/posts/Snapcast_jsonrpc_rce |
History
Wed, 04 Sep 2024 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-94 |
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-01-23T00:00:00
Updated: 2024-09-04T19:29:33.095Z
Reserved: 2023-06-21T00:00:00
Link: CVE-2023-36177
Vulnrichment
Updated: 2024-08-02T16:37:41.337Z
NVD
Status : Modified
Published: 2024-01-23T22:15:16.390
Modified: 2024-11-21T08:09:22.853
Link: CVE-2023-36177
Redhat
No data.