Vulnerability Description
Ampache is a web based audio/video streaming application and file manager. Versions prior to 4.4.1 allow unauthenticated access to Ampache using the subsonic API. To successfully make the attack you must use a username that is not part of the site to bypass the auth checks. For more details and workaround guidance see the referenced GitHub security advisory.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ampache | Ampache | < 4.4.1 |
Related Weaknesses (CWE)
References
- https://github.com/ampache/ampache/security/advisories/GHSA-p9pm-j95j-5mjfExploitMitigationThird Party Advisory
- https://github.com/ampache/ampache/security/advisories/GHSA-p9pm-j95j-5mjfExploitMitigationThird Party Advisory
FAQ
What is CVE-2021-21399?
CVE-2021-21399 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Ampache is a web based audio/video streaming application and file manager. Versions prior to 4.4.1 allow unauthenticated access to Ampache using the subsonic API. To successfully make the attack you m...
How severe is CVE-2021-21399?
CVE-2021-21399 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-21399?
Check the references section above for vendor advisories and patch information. Affected products include: Ampache Ampache.