Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3622 | Navidrome is an open source web-based music collection server and streamer. Navidrome stores the JWT secret in plaintext in the navidrome.db database file under the property table. This practice introduces a security risk because anyone with access to the database file can retrieve the secret. This vulnerability is fixed in 0.54.1. |
Github GHSA |
GHSA-xwx7-p63r-2rj8 | Navidrome Stores JWT Secret in Plaintext in navidrome.db |
Tue, 26 Aug 2025 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:navidrome:navidrome:*:*:*:*:*:*:*:* |
Tue, 24 Dec 2024 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 23 Dec 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Navidrome is an open source web-based music collection server and streamer. Navidrome stores the JWT secret in plaintext in the navidrome.db database file under the property table. This practice introduces a security risk because anyone with access to the database file can retrieve the secret. This vulnerability is fixed in 0.54.1. | |
| Title | Navidrome Stores JWT Secret in Plaintext in navidrome.db | |
| Weaknesses | CWE-312 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-12-24T01:35:29.314Z
Reserved: 2024-12-20T17:34:56.867Z
Link: CVE-2024-56362
Updated: 2024-12-24T01:35:24.614Z
Status : Analyzed
Published: 2024-12-23T18:15:07.617
Modified: 2025-08-26T01:56:50.763
Link: CVE-2024-56362
No data.
OpenCVE Enrichment
Updated: 2025-07-13T11:31:46Z
EUVD
Github GHSA