Vulnerability Description
Jellyfin up to v10.7.7 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /Repositories. This vulnerability allows attackers to access network resources and sensitive information via a crafted POST request.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jellyfin | Jellyfin | <= 10.7.7 |
Related Weaknesses (CWE)
References
- http://jellyfin.comBroken Link
- https://gist.github.com/b33t1e/5c067e0538a0b712dc3d59bd4b9a5952
- https://github.com/jellyfin/jellyfinProduct
- https://notes.sjtu.edu.cn/s/yJ9lPk09aExploitThird Party Advisory
- http://jellyfin.comBroken Link
- https://gist.github.com/b33t1e/5c067e0538a0b712dc3d59bd4b9a5952
- https://github.com/jellyfin/jellyfinProduct
- https://notes.sjtu.edu.cn/s/yJ9lPk09aExploitThird Party Advisory
FAQ
What is CVE-2023-27161?
CVE-2023-27161 is a vulnerability with a CVSS score of 7.5 (HIGH). Jellyfin up to v10.7.7 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /Repositories. This vulnerability allows attackers to access network resources and sensitive inf...
How severe is CVE-2023-27161?
CVE-2023-27161 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-27161?
Check the references section above for vendor advisories and patch information. Affected products include: Jellyfin Jellyfin.