Impact
AzuraCast prior to version 0.23.8 suffers from a broken access control flaw in the GET /api/station/{id}/vue/profile endpoint. Users who are authenticated but only possess View Station Page permission can retrieve plaintext Icecast/Shoutcast administrative, source, and relay passwords. This allows an attacker to gain the necessary admin credentials to log in to the backend media server with elevated privileges. The vulnerability is a classic example of improper access control (CWE-200) and can lead to the compromise of the streaming service’s administration layer.
Affected Systems
The affected software is AzuraCast v0.23.7 and earlier. Vendors and products listed include AzuraCast:AzuraCast. No additional version details are provided beyond the pre‑0.23.8 range.
Risk and Exploitability
The CVSS score of 7.2 indicates moderate to high severity. EPSS metadata is not available, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the likely attack vector is an authenticated user with only View Station Page permission exploiting the GET /api/station/{id}/vue/profile endpoint, which returns plaintext administrative credentials. Because many users possess view‑only access, exploitation is straightforward once an attacker has authenticated credentials. The vulnerability therefore poses a significant risk of unauthorized disclosure of admin credentials and potential takeover of the Icecast/Shoutcast backend.
OpenCVE Enrichment