CVE-2023-51665: Audiobookshelf vulnerable to Blind SSRF in `Auth.js`
Published Dec 27, 2023
·Updated
Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.7.0, Audiobookshelf is vulnerable to unauthenticated blind server-side request (SSRF) vulnerability in Auth.js. This vulnerability has been addressed in version 2.7.0. There are no known workarounds for this vulnerability.
Affected Software
1 affected component
Audiobookshelf Audiobookshelf<2.7.0
Remediation
Event History
Dec 27, 2023
CVE Published
05:26 PM
Data Sourced
05:26 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-51665?
CVE-2023-51665 is a critical vulnerability that allows unauthenticated blind SSRF attacks.
2
How do I fix CVE-2023-51665?
To fix CVE-2023-51665, upgrade Audiobookshelf to version 2.7.0 or later.
3
What versions of Audiobookshelf are affected by CVE-2023-51665?
CVE-2023-51665 affects all versions of Audiobookshelf prior to 2.7.0.
4
Is there a workaround for CVE-2023-51665?
There are no known workarounds for CVE-2023-51665, so upgrading is essential.
5
What kind of attacks can CVE-2023-51665 lead to?
CVE-2023-51665 can lead to SSRF attacks, potentially allowing attackers to access internal services.