Skip to content

Blind SSRF in `Auth.js` (`GHSL-2023-266`)

Moderate
advplyr published GHSA-gjgj-98v3-47pg Dec 23, 2023

Package

audiobookshelf

Affected versions

2.6.0

Patched versions

2.7.0

Description

Summary

Audiobookshelf v2.6.0 is vulnerable to unauthenticated blind server-side request (SSRF) vulnerability in Auth.js.

Severity

Moderate

CVE ID

CVE-2023-51665

Weaknesses

Credits