Skip to content

Blind SSRF in `podcastUtils.js` (`GHSL-2023-267`)

Low
advplyr published GHSA-jhjx-c3wx-q2x7 Dec 23, 2023

Package

audiobookshelf

Affected versions

2.6.0

Patched versions

2.7.0

Description

Summary

Audiobookshelf v2.6.0 is vulnerable to unauthenticated blind server-side request (SSRF) vulnerability in podcastUtils.js.

Severity

Low

CVE ID

CVE-2023-51697

Weaknesses

Credits