Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-29490

Опубликовано: 06 мая 2021
Источник: nvd
CVSS3: 5.8
CVSS2: 5
EPSS Критический

Описание

Jellyfin is a free software media system that provides media from a dedicated server to end-user devices via multiple apps. Verions prior to 10.7.3 vulnerable to unauthenticated Server-Side Request Forgery (SSRF) attacks via the imageUrl parameter. This issue potentially exposes both internal and external HTTP servers or other resources available via HTTP GET that are visible from the Jellyfin server. The vulnerability is patched in version 10.7.3. As a workaround, disable external access to the API endpoints /Items/*/RemoteImages/Download, /Items/RemoteSearch/Image and /Images/Remote via reverse proxy, or limit to known-friendly IPs.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:jellyfin:jellyfin:*:*:*:*:*:*:*:*
Версия до 10.7.3 (исключая)

EPSS

Процентиль: 100%
0.91997
Критический

5.8 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 5.8
debian
почти 5 лет назад

Jellyfin is a free software media system that provides media from a de ...

EPSS

Процентиль: 100%
0.91997
Критический

5.8 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-918