Unrated severityNVD Advisory· Published Apr 8, 2024· Updated Sep 3, 2024
Clients removed during unpairing process may regain access if Sunshine was not restarted
CVE-2024-31221
Description
Sunshine is a self-hosted game stream host for Moonlight. Starting in version 0.10.0 and prior to version 0.23.0, after unpairing all devices in the web UI interface and then pairing only one device, all of the previously devices will be temporarily paired. Version 0.23.0 contains a patch for the issue. As a workaround, restarting Sunshine after unpairing all devices prevents the vulnerability.
Affected products
1- Range: >= 0.10.0, < 0.23.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/LizardByte/Sunshine/commit/b7aa8119f1471844dccdf73a8b6f7efc9baddb5emitrex_refsource_MISC
- github.com/LizardByte/Sunshine/issues/2305mitrex_refsource_MISC
- github.com/LizardByte/Sunshine/pull/2365mitrex_refsource_MISC
- github.com/LizardByte/Sunshine/security/advisories/GHSA-v8gw-jw28-v55mmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.