Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Hydragyrum

#44750of 53,630
5.8Total CVSS
Vulnerabilities · 1
PT-2021-18251
5.8
2021-05-05
Jellyfin · Jellyfin · CVE-2021-29490
Name of the Vulnerable Software and Affected Versions: Jellyfin versions prior to 10.7.3 Description: The issue allows unauthenticated Server-Side Request Forgery (SSRF) attacks via the `imageUrl` parameter, potentially exposing internal and external HTTP servers or other resources available via HTTP `GET` that are visible from the Jellyfin server. Recommendations: For versions prior to 10.7.3, update to version 10.7.3 to resolve the issue. As a temporary workaround, consider disabling external access to the API endpoints "/Items/*/RemoteImages/Download", "/Items/RemoteSearch/Image", and "/Images/Remote" via reverse proxy, or limit access to known-friendly IPs.