CVE-2019-19833: CSRF
Published Dec 18, 2019
·Updated
In Tautulli 2.1.9, CSRF in the /shutdown URI allows an attacker to shut down the remote media server. (Also, anonymous access can be achieved in applications that do not have a user login area).
Affected Software
1 affected component
Tautulli Tautulli=2.1.9
Event History
Dec 18, 2019
CVE Published
via MITRE·05:08 PM
Data Sourced
via MITRE·05:08 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-19833?
CVE-2019-19833 has a medium severity level due to its potential for remote code execution via CSRF.
2
How do I fix CVE-2019-19833?
To fix CVE-2019-19833, upgrade Tautulli to version 2.1.10 or higher where the vulnerability is addressed.
3
What does CVE-2019-19833 allow an attacker to do?
CVE-2019-19833 allows an attacker to shut down the remote media server via CSRF attacks.
4
Can CVE-2019-19833 be exploited without user authentication?
Yes, CVE-2019-19833 can be exploited in applications that do not have a user login area, allowing anonymous access.
5
Which version of Tautulli is affected by CVE-2019-19833?
Tautulli version 2.1.9 is the vulnerable version affected by CVE-2019-19833.