Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/azuracast/AzuraCast

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

AzuraCast versions prior to 0.23.4 have a code injection vulnerability in the ConfigWriter::cleanUpString() method. This flaw allows authenticated users with Media or Profile permissions to inject arbitrary Liquidsoap code via unsanitized string interpolation sequences. Exploitation can lead to execution of shell commands as the azuracast user when the station restarts.

Join the discussion

AzuraCast versions before 0.23.8 have a broken access control vulnerability in the GET /api/station/{id}/vue/profile endpoint. This flaw allows authenticated users with only View Station Page permission to access Icecast/Shoutcast admin, source, and relay passwords in plaintext. Attackers can use the exposed admin password to authenticate to the Icecast admin interface without needing Broadcasting permission.

Join the discussion

AzuraCast versions before 0.23.8 contain a server-side request forgery (SSRF) vulnerability in the station webhook URL validation. The validation incorrectly rejects only literal link-local IP addresses but allows loopback and private network addresses, enabling a user with station-scoped WebHooks permission to configure webhooks targeting internal or private network resources. This can cause the server to send HTTP POST requests with station data to unintended internal endpoints. The vulnerability can be triggered on demand via a specific test endpoint. No patch was available at the time of the advisory.

Join the discussion

AzuraCast versions through 0.23.x have a command injection vulnerability in the Liquidsoap configuration generation for live recording. The vulnerability arises because the streamer username is not properly quoted in process.run calls, allowing authenticated station users with Streamers and Profile permissions to execute arbitrary commands as the Liquidsoap process user when recording ends.

Join the discussion

AzuraCast versions prior to 0.23.8 have a DQL injection vulnerability in the sortOrder API parameter of AbstractSearchableListAction.php. This flaw allows attackers to inject arbitrary Doctrine Query Language expressions, potentially exposing sensitive database information such as user credentials and station settings.

Join the discussion

AzuraCast versions before 0.23.8 have a vulnerability in the public On-Demand download endpoint that does not properly enforce playlist-level access controls. This flaw allows unauthenticated users to download media files that are meant to be excluded from On-Demand-enabled playlists, bypassing intended access restrictions and exposing private or restricted audio content.

Join the discussion

AzuraCast versions prior to 0.23.6 have a vulnerability where the Liquidsoap API endpoint lacks the RequireInternalConnection middleware and incorrectly derives the AutoDJ flag from header presence instead of a validated value. This allows users with View station permission to inject arbitrary now-playing metadata, disrupt live broadcasts, and disclose filesystem paths.

Join the discussion

AzuraCast versions prior to 0.23.6 contain a code injection vulnerability in the remote relay password field. This arises from incomplete migration from the vulnerable cleanUpString method to toRawString. Attackers with RemoteRelays station permission can exploit this to inject nested Liquidsoap interpolation syntax, enabling arbitrary code execution within the Liquidsoap process, disclosure of internal API keys, or disruption of station operations.

Join the discussion

AzuraCast versions before 0.23.8 have a server-side request forgery (SSRF) and local file read vulnerability in the AutoDJ remote playlist fetch functionality. A user with Media permission can craft a playlist referencing a file:// URL or internal HTTP endpoints, causing the backend to read local files or internal resources without proper restrictions. This can disclose sensitive files such as /etc/passwd or application environment files to users with Broadcasting permission. No patch was available at the time of publication.

Join the discussion

AzuraCast versions prior to 0.23.6 have a missing permission check vulnerability in the GET /api/station/{station_id}/file/{id}/play endpoint. This flaw allows authenticated users to download media files from any station, including those they do not have permission to access. Attackers can enumerate media files using sequential IDs and exfiltrate entire media libraries of unauthorized stations.

Join the discussion

Showing 1 to 10 of 10 results

Filters:Package: pkg:github/azuracast/AzuraCast
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses