Sunshine is a self-hosted game stream host for Moonlight. Starting in version 0.10.0 and prior to version 0.23.0, after unpairing all devices in the web UI interface and then pairing only one device, all of the previously devices will be temporarily paired. Version 0.23.0 contains a patch for the issue. As a workaround, restarting Sunshine after unpairing all devices prevents the vulnerability.
References
Link | Resource |
---|---|
https://github.com/LizardByte/Sunshine/commit/b7aa8119f1471844dccdf73a8b6f7efc9baddb5e | Patch |
https://github.com/LizardByte/Sunshine/issues/2305 | Exploit Issue Tracking |
https://github.com/LizardByte/Sunshine/pull/2365 | Issue Tracking Patch |
https://github.com/LizardByte/Sunshine/security/advisories/GHSA-v8gw-jw28-v55m | Vendor Advisory |
https://github.com/LizardByte/Sunshine/commit/b7aa8119f1471844dccdf73a8b6f7efc9baddb5e | Patch |
https://github.com/LizardByte/Sunshine/issues/2305 | Exploit Issue Tracking |
https://github.com/LizardByte/Sunshine/pull/2365 | Issue Tracking Patch |
https://github.com/LizardByte/Sunshine/security/advisories/GHSA-v8gw-jw28-v55m | Vendor Advisory |
Configurations
History
11 Sep 2025, 21:41
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:lizardbyte:sunshine:*:*:*:*:*:*:*:* | |
First Time |
Lizardbyte sunshine
Lizardbyte |
|
References | () https://github.com/LizardByte/Sunshine/commit/b7aa8119f1471844dccdf73a8b6f7efc9baddb5e - Patch | |
References | () https://github.com/LizardByte/Sunshine/issues/2305 - Exploit, Issue Tracking | |
References | () https://github.com/LizardByte/Sunshine/pull/2365 - Issue Tracking, Patch | |
References | () https://github.com/LizardByte/Sunshine/security/advisories/GHSA-v8gw-jw28-v55m - Vendor Advisory |
21 Nov 2024, 09:13
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/LizardByte/Sunshine/commit/b7aa8119f1471844dccdf73a8b6f7efc9baddb5e - | |
References | () https://github.com/LizardByte/Sunshine/issues/2305 - | |
References | () https://github.com/LizardByte/Sunshine/pull/2365 - | |
References | () https://github.com/LizardByte/Sunshine/security/advisories/GHSA-v8gw-jw28-v55m - |
08 Apr 2024, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-04-08 15:15
Updated : 2025-09-11 21:41
NVD link : CVE-2024-31221
Mitre link : CVE-2024-31221
CVE.ORG link : CVE-2024-31221
JSON object : View
Products Affected
lizardbyte
- sunshine
CWE
CWE-384
Session Fixation