In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Missing Authorization vulnerabilities in an interactive lesson.
Start learningUpgrade azuracast/azuracast to version 0.23.6 or higher.
Affected versions of this package are vulnerable to Missing Authorization in the /api/internal/{station_id}/liquidsoap/{action} endpoint due to missing internal connection requirements and improper validation of the X-Liquidsoap-Api-Key header. An attacker can inject arbitrary metadata, disrupt live broadcasts, fake DJ connections, and disclose absolute filesystem paths by sending crafted requests with only basic station view permissions.