CVE-2021-32833: GHSL-2021-051: Unauthenticated file read in Emby Server - CVE-2021-32833
Emby Server allows unauthenticated file read.
Other sources
Emby Server is a personal media server with apps on many devices. In Emby Server on Windows there is a set of arbitrary file read vulnerabilities. This vulnerability is known to exist in version 4.6.4.0 and may not be patched in later versions. Known vulnerable routes are /Videos/Id/hls/PlaylistId/SegmentId.SegmentContainer, /Images/Ratings/theme/name and /Images/MediaInfo/theme/name. For more details including proof of concept code, refer to the referenced GHSL-2021-051. This issue may lead to unauthorized access to the system especially when Emby Server is configured to be accessible from the Internet.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-32833?
CVE-2021-32833 is an arbitrary file read vulnerability in Emby Server on Windows.
What is Emby Server?
Emby Server is a personal media server with apps on many devices.
Which version of Emby Server is affected?
Version 4.6.4.0 of Emby Server on Windows is known to be affected.
How severe is CVE-2021-32833?
CVE-2021-32833 has a severity rating of 8.6 (high).
How can I fix CVE-2021-32833?
There is currently no patch available for CVE-2021-32833, so it is recommended to update to a version of Emby Server that is not vulnerable if possible, and to take necessary precautions to protect your system.