← Back to CVE List

CVE-2021-21399

Published: 2021-04-13T20:15Z
Last Modified: 2024-11-21T05:48Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Ampache is a web based audio/video streaming application and file manager. Versions prior to 4.4.1 allow unauthenticated access to Ampache using the subsonic API. To successfully make the attack you must use a username that is not part of the site to bypass the auth checks. For more details and workaround guidance see the referenced GitHub security advisory. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt