Vulnerabilities > Airsonic Project

DATE CVE VULNERABILITY TITLE RISK
2019-04-07 CVE-2019-10908 Cryptographic Issues vulnerability in Airsonic Project Airsonic 10.2.1
In Airsonic 10.2.1, RecoverController.java generates passwords via org.apache.commons.lang.RandomStringUtils, which uses java.util.Random internally.
network
low complexity
airsonic-project CWE-310
7.5
2019-04-07 CVE-2019-10907 Inadequate Encryption Strength vulnerability in Airsonic Project Airsonic 10.2.1
Airsonic 10.2.1 uses Spring's default remember-me mechanism based on MD5, with a fixed key of airsonic in GlobalSecurityConfig.java.
network
low complexity
airsonic-project CWE-326
5.0
2019-04-04 CVE-2018-20222 XXE vulnerability in Airsonic Project Airsonic
XXE issue in Airsonic before 10.1.2 during parse.
network
low complexity
airsonic-project CWE-611
7.5