PT-2021-19965 · Unknown · Emby Server
Jarlob
+1
·
Published
2021-09-09
·
Updated
2021-09-16
·
CVE-2021-32833
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Emby Server version 4.6.4.0
Description
The issue concerns arbitrary file read vulnerabilities in Emby Server on Windows. Vulnerable routes include "Videos/Id/hls/PlaylistId/SegmentId.SegmentContainer", "Images/Ratings/theme/name", and "Images/MediaInfo/theme/name". This may lead to unauthorized access to the system, especially when Emby Server is configured to be accessible from the Internet.
Recommendations
For Emby Server version 4.6.4.0, consider restricting access to the vulnerable routes "Videos/Id/hls/PlaylistId/SegmentId.SegmentContainer", "Images/Ratings/theme/name", and "Images/MediaInfo/theme/name" to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Emby Server