CVE-2023-30627
- EPSS 0.79%
- Veröffentlicht 24.04.2023 21:15:09
- Zuletzt bearbeitet 21.11.2024 08:00:32
jellyfin-web is the web client for Jellyfin, a free-software media system. Starting in version 10.1.0 and prior to version 10.8.10, a stored cross-site scripting vulnerability in device.js can be used to make arbitrary calls to the `REST` endpoints w...
CVE-2023-30626
- EPSS 0.99%
- Veröffentlicht 24.04.2023 21:15:09
- Zuletzt bearbeitet 21.11.2024 08:00:32
Jellyfin is a free-software media system. Versions starting with 10.8.0 and prior to 10.8.10 and prior have a directory traversal vulnerability inside the `ClientLogController`, specifically `/ClientLog/Document`. When combined with a cross-site scri...
CVE-2023-27161
- EPSS 1.39%
- Veröffentlicht 10.03.2023 16:15:11
- Zuletzt bearbeitet 28.02.2025 22:15:38
Jellyfin up to v10.7.7 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /Repositories. This vulnerability allows attackers to access network resources and sensitive information via a crafted POST request.
CVE-2023-23636
- EPSS 0.53%
- Veröffentlicht 03.02.2023 01:15:14
- Zuletzt bearbeitet 26.03.2025 19:15:23
In Jellyfin 10.8.x through 10.8.3, the name of a playlist is vulnerable to stored XSS. This allows an attacker to steal access tokens from the localStorage of the victim.
CVE-2023-23635
- EPSS 0.54%
- Veröffentlicht 03.02.2023 01:15:14
- Zuletzt bearbeitet 26.03.2025 19:15:22
In Jellyfin 10.8.x through 10.8.3, the name of a collection is vulnerable to stored XSS. This allows an attacker to steal access tokens from the localStorage of the victim.
CVE-2022-35910
- EPSS 0.29%
- Veröffentlicht 19.08.2022 13:15:08
- Zuletzt bearbeitet 21.11.2024 07:11:56
In Jellyfin before 10.8, stored XSS allows theft of an admin access token.
CVE-2022-35909
- EPSS 0.78%
- Veröffentlicht 19.08.2022 13:15:08
- Zuletzt bearbeitet 21.11.2024 07:11:56
In Jellyfin before 10.8, the /users endpoint has incorrect access control for admin functionality.
CVE-2021-29490
- EPSS 88.18%
- Veröffentlicht 06.05.2021 13:15:12
- Zuletzt bearbeitet 21.11.2024 06:01:14
Jellyfin is a free software media system that provides media from a dedicated server to end-user devices via multiple apps. Verions prior to 10.7.3 vulnerable to unauthenticated Server-Side Request Forgery (SSRF) attacks via the imageUrl parameter. T...
CVE-2021-21402
- EPSS 90.47%
- Veröffentlicht 23.03.2021 20:15:13
- Zuletzt bearbeitet 21.11.2024 05:48:17
Jellyfin is a Free Software Media System. In Jellyfin before version 10.7.1, with certain endpoints, well crafted requests will allow arbitrary file read from a Jellyfin server's file system. This issue is more prevalent when Windows is used as the h...