CVE-2023-23635: XSS
In Jellyfin 10.8.x through 10.8.3, the name of a collection is vulnerable to stored XSS. This allows an attacker to steal access tokens from the localStorage of the victim.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-23635?
CVE-2023-23635 is a vulnerability in Jellyfin 10.8.x through 10.8.3, where the name of a collection is vulnerable to stored XSS.
How does CVE-2023-23635 affect Jellyfin?
CVE-2023-23635 allows an attacker to steal access tokens from the localStorage of a victim.
How severe is CVE-2023-23635?
CVE-2023-23635 has a severity score of 5.4, which is considered medium.
How do I fix CVE-2023-23635?
To fix CVE-2023-23635, update Jellyfin to version 10.8.4 or later.
Where can I find more information about CVE-2023-23635?
You can find more information about CVE-2023-23635 at the following references: [GitHub Issue](https://github.com/jellyfin/jellyfin-web/issues/3788), [HEROLAB Security Advisories](https://herolab.usd.de/security-advisories/usd-2022-0031/).