CVE-2024-31221

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-31221
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-31221.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-31221
Aliases
  • GHSA-v8gw-jw28-v55m
Published
2024-04-08T15:10:17Z
Modified
2025-11-04T19:33:10Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:L CVSS Calculator
Summary
Clients removed during unpairing process may regain access if Sunshine was not restarted
Details

Sunshine is a self-hosted game stream host for Moonlight. Starting in version 0.10.0 and prior to version 0.23.0, after unpairing all devices in the web UI interface and then pairing only one device, all of the previously devices will be temporarily paired. Version 0.23.0 contains a patch for the issue. As a workaround, restarting Sunshine after unpairing all devices prevents the vulnerability.

Database specific
{
    "cwe_ids": [
        "CWE-384"
    ]
}
References

Affected packages

Git / github.com/lizardbyte/sunshine

Affected ranges

Type
GIT
Repo
https://github.com/lizardbyte/sunshine
Events