Use of insecure hashing algorithm in the Gravatar's service in Navidrome v0.52.3 allows attackers to manipulate a user's account information.
The Gravatar service identifies user profiles based on a hash of the email address. Navidrome v0.52.3 uses a weak, unsecured hashing algorithm (e.g., MD5) in this process, which is vulnerable to collisions or reversal. An attacker can exploit this weakness to associate false profile data with a target user's account, effectively manipulating information displayed in the application.
An attacker without any authentication can manipulate user account information (e.g., avatar or profile data retrieved from Gravatar), which constitutes a violation of account data integrity and confidentiality.
Apply patches available from the vendor according to the references. It is recommended to update to a newer version of Navidrome in which a secure hashing algorithm is implemented in the Gravatar integration.
Navidrome version 0.52.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NNavidrome
APPNavidrome≤ 0.52.3
Related vulnerabilities
Navidrome: niekontrolowany wzrost pamięci i wyczerpanie dysku przez parametr rozmiaru obrazka
SQL Injection i ORM Leak w Navidrome — wyciek danych i brute-force haseł
Navidrome is an open source web-based music collection server and streamer. Versions 0.55.0 through 0.55.2 hav...
Navidrome is an open source web-based music collection server and streamer. A permission verification flaw in ...
Navidrome is an open source web-based music collection server and streamer. Navidrome stores the JWT secret in...