Описание
Jellyfin is a system for managing and streaming media. Prior to version 10.8.13, the /System/MediaEncoder/Path endpoint executes an arbitrary file using ProcessStartInfo via the ValidateVersion function. A malicious administrator can setup a network share and supply a UNC path to /System/MediaEncoder/Path which points to an executable on the network share, causing Jellyfin server to run the executable in the local context. The endpoint was removed in version 10.8.13.
Ссылки
- Patch
- ExploitVendor Advisory
- ExploitThird Party Advisory
- Patch
- ExploitVendor Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 10.8.13 (исключая)
cpe:2.3:a:jellyfin:jellyfin:*:*:*:*:*:*:*:*
EPSS
Процентиль: 73%
0.00744
Низкий
7.2 High
CVSS3
Дефекты
CWE-77
Связанные уязвимости
CVSS3: 7.2
debian
около 2 лет назад
Jellyfin is a system for managing and streaming media. Prior to versio ...
EPSS
Процентиль: 73%
0.00744
Низкий
7.2 High
CVSS3
Дефекты
CWE-77