CVE-2024-31221: Clients removed during unpairing process may regain access if Sunshine was not restarted

Published Apr 8, 2024
·
Updated

Sunshine is a self-hosted game stream host for Moonlight. Starting in version 0.10.0 and prior to version 0.23.0, after unpairing all devices in the web UI interface and then pairing only one device, all of the previously devices will be temporarily paired. Version 0.23.0 contains a patch for the issue. As a workaround, restarting Sunshine after unpairing all devices prevents the vulnerability.

Affected Software

2 affected components
Sunshine Sunshine>=0.10.0<0.23.0
LizardByte Sunshine>=0.10.0<0.23.0

Event History

Apr 8, 2024
CVE Published
via MITRE·03:10 PM
Data Sourced
via MITRE·03:10 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-31221?

CVE-2024-31221 has been rated as a medium severity vulnerability due to its potential impact on device pairing integrity.

2

How do I fix CVE-2024-31221?

To fix CVE-2024-31221, upgrade to Sunshine version 0.23.0 or later, which addresses the pairing issue.

3

What are the symptoms of CVE-2024-31221?

Symptoms of CVE-2024-31221 include previously unpaired devices being temporarily paired after connecting a new device.

4

Who is affected by CVE-2024-31221?

CVE-2024-31221 affects users of Sunshine versions between 0.10.0 and 0.23.0.

5

Is there a workaround for CVE-2024-31221?

Currently, there is no documented workaround for CVE-2024-31221, and updating to the latest version is recommended.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203