CVE-2024-31221: Clients removed during unpairing process may regain access if Sunshine was not restarted
Sunshine is a self-hosted game stream host for Moonlight. Starting in version 0.10.0 and prior to version 0.23.0, after unpairing all devices in the web UI interface and then pairing only one device, all of the previously devices will be temporarily paired. Version 0.23.0 contains a patch for the issue. As a workaround, restarting Sunshine after unpairing all devices prevents the vulnerability.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-31221?
CVE-2024-31221 has been rated as a medium severity vulnerability due to its potential impact on device pairing integrity.
How do I fix CVE-2024-31221?
To fix CVE-2024-31221, upgrade to Sunshine version 0.23.0 or later, which addresses the pairing issue.
What are the symptoms of CVE-2024-31221?
Symptoms of CVE-2024-31221 include previously unpaired devices being temporarily paired after connecting a new device.
Who is affected by CVE-2024-31221?
CVE-2024-31221 affects users of Sunshine versions between 0.10.0 and 0.23.0.
Is there a workaround for CVE-2024-31221?
Currently, there is no documented workaround for CVE-2024-31221, and updating to the latest version is recommended.