WS-2023-0293
Published:May 15, 2026
Updated:May 15, 2026
A Broken Authentication vulnerability exists in azuracast through 0.18.5. An attacker is able to get sensitive information of Administration such as CPU stats.
Affected Packages
azuracast/azuracast (PHP):
Affected version(s) =dev-snyk-fix-522201b88ae70b5d02a44c88d89ec942 <dev-snyk-fix-d274cad45ec9812bd1860f4e02b1105fFix Suggestion:
Update to version dev-snyk-fix-d274cad45ec9812bd1860f4e02b1105fazuracast/azuracast (PHP):
Affected version(s) =dev-feature/webcast-v1 <dev-pre-1.4.0Fix Suggestion:
Update to version dev-pre-1.4.0azuracast/azuracast (PHP):
Affected version(s) =dev-Help-Logs <dev-Known-IssuesFix Suggestion:
Update to version dev-Known-Issuesazuracast/azuracast (PHP):
Affected version(s) =dev-stable <dev-stale-changeFix Suggestion:
Update to version dev-stale-changeazuracast/azuracast (PHP):
Affected version(s) =dev-feature/yellowpages <dev-fix-#4674Fix Suggestion:
Update to version dev-fix-#4674azuracast/azuracast (PHP):
Affected version(s) =dev-main <dev-masterFix Suggestion:
Update to version dev-masterazuracast/azuracast (PHP):
Affected version(s) =dev-test-turbo-drive <dev-workflow-staleFix Suggestion:
Update to version dev-workflow-staleazuracast/azuracast (PHP):
Affected version(s) >=0.15.0 <0.19.0Fix Suggestion:
Update to version 0.19.0azuracast/azuracast (PHP):
Affected version(s) =dev-feature/web-updater <dev-feature/whole-page-vueFix Suggestion:
Update to version dev-feature/whole-page-vueazuracast/azuracast (PHP):
Affected version(s) =dev-feature/per-record-backups <dev-feature/php-ffmpegFix Suggestion:
Update to version dev-feature/php-ffmpegazuracast/azuracast (PHP):
Affected version(s) =dev-feature/centrifugo <dev-feature/concurrent-syncFix Suggestion:
Update to version dev-feature/concurrent-syncazuracast/azuracast (PHP):
Affected version(s) =dev-feature/liquidsoap-2.2.x <dev-update-liquidsoap-to-66914f5-2.2.0Fix Suggestion:
Update to version dev-update-liquidsoap-to-66914f5-2.2.0azuracast/azuracast (PHP):
Affected version(s) =dev-feature/acme_improvements <dev-feature/annotationsFix Suggestion:
Update to version dev-feature/annotationsazuracast/azuracast (PHP):
Affected version(s) =dev-feature/vue3 <dev-snyk-upgrade-12772c67afa2125861a56f90fc93e67bFix Suggestion:
Update to version dev-snyk-upgrade-12772c67afa2125861a56f90fc93e67bazuracast/azuracast (PHP):
Affected version(s) =dev-feature/master_me <dev-feature/materialize_upgradeFix Suggestion:
Update to version dev-feature/materialize_upgradeazuracast/azuracast (PHP):
Affected version(s) =dev-update-to-liquidsoap-2.2.0-af6b0a9 <dev-dev-ls2.3.xFix Suggestion:
Update to version dev-dev-ls2.3.xazuracast/azuracast (PHP):
Affected version(s) =dev-feature/master_me_lv2 <dev-feature/media_meta_overhaul_2Fix Suggestion:
Update to version dev-feature/media_meta_overhaul_2azuracast/azuracast (PHP):
Affected version(s) =dev-feature/rr_again <dev-feature/rrule-schedulerFix Suggestion:
Update to version dev-feature/rrule-schedulerRelated Resources (1)
Do you need more information?
Contact UsCVSS v4
Base Score:
6.9
Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
Vulnerable System Confidentiality
LOW
Vulnerable System Integrity
NONE
Vulnerable System Availability
NONE
Subsequent System Confidentiality
NONE
Subsequent System Integrity
NONE
Subsequent System Availability
NONE
CVSS v3
Base Score:
5.3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE