audiobookshelf is a self-hosted audiobook and podcast server. A non-admin user is not allowed to create libraries (or access only the ones they have permission to). However, the `LibraryController` is missing the check for admin user and thus allows a path traversal issue. Allowing non-admin users to write to any directory in the system can be seen as a form of path traversal. However, since it can be restricted to only admin permissions, fixing this is relatively simple and falls more into the realm of Role-Based Access Control (RBAC). This issue has been addressed in release version 2.13.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.
Metrics
Affected Vendors & Products
References
History
Fri, 13 Sep 2024 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Audiobookshelf
Audiobookshelf audiobookshelf |
|
CPEs | cpe:2.3:a:audiobookshelf:audiobookshelf:*:*:*:*:*:*:*:* | |
Vendors & Products |
Audiobookshelf
Audiobookshelf audiobookshelf |
Tue, 03 Sep 2024 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Advplyr
Advplyr audiobookshelf |
|
CPEs | cpe:2.3:a:advplyr:audiobookshelf:*:*:*:*:*:*:*:* | |
Vendors & Products |
Advplyr
Advplyr audiobookshelf |
|
Metrics |
ssvc
|
Mon, 02 Sep 2024 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | audiobookshelf is a self-hosted audiobook and podcast server. A non-admin user is not allowed to create libraries (or access only the ones they have permission to). However, the `LibraryController` is missing the check for admin user and thus allows a path traversal issue. Allowing non-admin users to write to any directory in the system can be seen as a form of path traversal. However, since it can be restricted to only admin permissions, fixing this is relatively simple and falls more into the realm of Role-Based Access Control (RBAC). This issue has been addressed in release version 2.13.0. All users are advised to upgrade. There are no known workarounds for this vulnerability. | |
Title | Path Traversal in audiobookshelf | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-09-02T16:21:07.372Z
Updated: 2024-09-03T14:18:32.336Z
Reserved: 2024-08-16T14:20:37.325Z
Link: CVE-2024-43797
Vulnrichment
Updated: 2024-09-03T14:18:17.511Z
NVD
Status : Analyzed
Published: 2024-09-02T18:15:36.073
Modified: 2024-09-13T19:49:33.803
Link: CVE-2024-43797
Redhat
No data.