CVE-2022-35909: High severity jellyfin vulnerability
Published Aug 19, 2022
·Updated
In Jellyfin before 10.8, the /users endpoint has incorrect access control for admin functionality.
Affected Software
1 affected component
Jellyfin Jellyfin<10.8
Remediation
Patch Available
Event History
Aug 19, 2022
CVE Published
via MITRE·11:52 AM
Data Sourced
via MITRE·11:52 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Jellyfin vulnerability?
The vulnerability ID is CVE-2022-35909.
2
What is the severity of CVE-2022-35909?
The severity of CVE-2022-35909 is high with a severity value of 8.8.
3
What is the affected software for CVE-2022-35909?
The affected software for CVE-2022-35909 is Jellyfin versions before 10.8.
4
What is the description of CVE-2022-35909?
CVE-2022-35909 is a vulnerability in Jellyfin before 10.8 where the /users endpoint has incorrect access control for admin functionality.
5
How can I fix CVE-2022-35909?
To fix CVE-2022-35909, it is recommended to update to Jellyfin version 10.8 or later.