Sunshine is a self-hosted game stream host for Moonlight. In 0.23.1 and earlier, Sunshine's pairing protocol implementation does not validate request order and is thereby vulnerable to a MITM attack, potentially allowing an unauthenticated attacker to pair a client by hijacking a legitimate pairing attempt. This bug may also be used by a remote attacker to crash Sunshine. This vulnerability is fixed in 2025.118.151840.
Metrics
Affected Vendors & Products
References
History
Tue, 21 Jan 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 20 Jan 2025 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Sunshine is a self-hosted game stream host for Moonlight. In 0.23.1 and earlier, Sunshine's pairing protocol implementation does not validate request order and is thereby vulnerable to a MITM attack, potentially allowing an unauthenticated attacker to pair a client by hijacking a legitimate pairing attempt. This bug may also be used by a remote attacker to crash Sunshine. This vulnerability is fixed in 2025.118.151840. | |
Title | Sunshine improperly enforces pairing protocol request order | |
Weaknesses | CWE-305 CWE-476 CWE-841 |
|
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-01-21T14:59:35.704Z
Reserved: 2024-10-31T14:12:45.788Z
Link: CVE-2024-51738

Updated: 2025-01-21T14:58:43.918Z

Status : Received
Published: 2025-01-20T16:15:27.667
Modified: 2025-01-20T16:15:27.667
Link: CVE-2024-51738

No data.