CVE-2024-56362

Navidrome is an open source web-based music collection server and streamer. Navidrome stores the JWT secret in plaintext in the navidrome.db database file under the property table. This practice introduces a security risk because anyone with access to the database file can retrieve the secret. This vulnerability is fixed in 0.54.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:navidrome:navidrome:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-12-23 18:15

Updated : 2025-08-26 01:56


NVD link : CVE-2024-56362

Mitre link : CVE-2024-56362

CVE.ORG link : CVE-2024-56362


JSON object : View

Products Affected

navidrome

  • navidrome
CWE
CWE-312

Cleartext Storage of Sensitive Information