CyberRota Analysis
AI-GeneratedVersions of gonic prior to 0.22.0 are vulnerable due to inadequate validation of administrator privileges in the startScan endpoint, enabling any authenticated user to initiate media library rescans. This flaw can lead to denial of service by allowing attackers to overload system resources through repeated calls to the endpoint. Organizations using gonic in multi-user environments should prioritize patching to mitigate potential disruptions.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
gonic versions before 0.22.0 fail to validate administrator privileges in the startScan endpoint, allowing any authenticated user to trigger media library rescans. Attackers can repeatedly call the startScan endpoint to force CPU and I/O-intensive filesystem operations, causing denial of service on multi-user instances.