CVE-2021-29490: Unauthenticated GET requests through Remote Image endpoints

Published May 5, 2021
·
Updated

Jellyfin is a free software media system that provides media from a dedicated server to end-user devices via multiple apps. Verions prior to 10.7.3 vulnerable to unauthenticated Server-Side Request Forgery (SSRF) attacks via the imageUrl parameter. This issue potentially exposes both internal and external HTTP servers or other resources available via HTTP GET that are visible from the Jellyfin server. The vulnerability is patched in version 10.7.3. As a workaround, disable external access to the API endpoints /Items//RemoteImages/Download, /Items/RemoteSearch/Image and /Images/Remote via reverse proxy, or limit to known-friendly IPs.

Affected Software

1 affected component
Jellyfin Jellyfin<10.7.3

Event History

May 5, 2021
CVE Published
via MITRE·06:25 PM
Data Sourced
via MITRE·06:25 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is CVE-2021-29490?

CVE-2021-29490 is a vulnerability in Jellyfin that allows unauthenticated Server-Side Request Forgery (SSRF) attacks via the imageUrl parameter.

2

How severe is CVE-2021-29490?

CVE-2021-29490 has a severity score of 5.8, which is classified as medium.

3

How does CVE-2021-29490 impact Jellyfin?

CVE-2021-29490 exposes both internal and external resources, potentially leading to unauthorized access or data leakage.

4

Which versions of Jellyfin are affected by CVE-2021-29490?

Versions prior to 10.7.3 of Jellyfin are vulnerable to CVE-2021-29490.

5

How can I fix CVE-2021-29490 in Jellyfin?

To fix CVE-2021-29490, update Jellyfin to version 10.7.3 or newer.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203