GHSL-2023-204: GHSL-2023-203_GHSL-2023-204: Several vulnerabilities in audiobookshelf
Audiobookshelf is vulnerable to server-side request forgery (SSRF), arbitrary file read (AFR) and arbitrary file deletion (AFD) depending on the permissions of the user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of GHSL-2023-204?
The severity of GHSL-2023-204 is rated at 60, indicating a moderate risk level.
What types of vulnerabilities are identified in GHSL-2023-204?
GHSL-2023-204 identifies several vulnerabilities including server-side request forgery (SSRF), arbitrary file read (AFR), and arbitrary file deletion (AFD).
How do I fix GHSL-2023-204?
To fix GHSL-2023-204, users should update Audiobookshelf to the latest version that addresses these vulnerabilities.
Who is affected by GHSL-2023-204?
Users of Audiobookshelf may be affected by GHSL-2023-204 depending on their user permissions.
What should I do if I can't update due to GHSL-2023-204?
If unable to update due to GHSL-2023-204, consider implementing strict access controls and monitoring for unauthorized access as a temporary mitigation.