CVE-2023-51697: Audiobookshelf vulnerable to Blind SSRF in `podcastUtils.js`
Published Dec 27, 2023
·Updated
Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.7.0, Audiobookshelf is vulnerable to unauthenticated blind server-side request (SSRF) vulnerability in podcastUtils.js. This vulnerability has been addressed in version 2.7.0. There are no known workarounds for this vulnerability.
Affected Software
1 affected component
Audiobookshelf Audiobookshelf<2.7.0
Remediation
Event History
Dec 27, 2023
CVE Published
05:26 PM
Data Sourced
05:26 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-51697?
CVE-2023-51697 is classified as a high-severity vulnerability due to its potential for unauthorized access.
2
How do I fix CVE-2023-51697?
To fix CVE-2023-51697, upgrade Audiobookshelf to version 2.7.0 or later.
3
What type of vulnerability is CVE-2023-51697?
CVE-2023-51697 is an unauthenticated blind server-side request forgery (SSRF) vulnerability.
4
Which versions of Audiobookshelf are affected by CVE-2023-51697?
The affected versions of Audiobookshelf are all versions prior to 2.7.0.
5
Is there a workaround for CVE-2023-51697?
There are no known workarounds to mitigate CVE-2023-51697, so upgrading is recommended.