CVE Feed

    Dashboard / CVE / CVE-2021-21402

    CVE-2021-21402

    Jellyfin is a Free Software Media System. In Jellyfin before version 10.7.1, with certain endpoints, well crafted requests will allow arbitrary file read from a Jellyfin server's file system. This issue is more prevalent when Windows is used as the host OS. Servers that are exposed to the public Internet are potentially at risk. This is fixed in version 10.7.1. As a workaround, users may be able to restrict some access by enforcing strict security permissions on their filesystem, however, it is recommended to update as soon as possible.

    Published:Mar 23, 2021
    Last Modified:Nov 21, 2024
    EPS:Mar 23, 2021
    EPSS Score:0.92168
    CVSS Score:7.7

    Affected Products

    Vendor
    Jellyfin
    Product
    Jellyfin

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High