CVE-2020-26948: SSRF
Published Oct 10, 2020
·Updated
Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter.
Affected Software
1 affected component
Emby Emby<4.5.0
Event History
Oct 10, 2020
CVE Published
via MITRE·08:12 PM
Data Sourced
via MITRE·08:12 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-26948?
CVE-2020-26948 has a medium severity rating, primarily due to its potential for server-side request forgery (SSRF).
2
How do I fix CVE-2020-26948?
To mitigate CVE-2020-26948, upgrade Emby Server to version 4.5.0 or later to eliminate the vulnerability.
3
What does CVE-2020-26948 affect?
CVE-2020-26948 affects Emby Server versions before 4.5.0 by allowing SSRF through a specific parameter.
4
What is SSRF in the context of CVE-2020-26948?
In the context of CVE-2020-26948, SSRF refers to a vulnerability that enables attackers to send requests from the server to internal resources.
5
Are there any potential impacts of CVE-2020-26948?
The impacts of CVE-2020-26948 include unauthorized access to internal services and potential data leakage due to SSRF.