CVE-2023-23636: XSS
Published Feb 3, 2023
·Updated
In Jellyfin 10.8.x through 10.8.3, the name of a playlist is vulnerable to stored XSS. This allows an attacker to steal access tokens from the localStorage of the victim.
Affected Software
2 affected componentsFixes available
Jellyfin Jellyfin>=10.8.0<=10.8.3
npm/jellyfin-web>=10.8.0<10.8.4
10.8.4
Remediation
Patch Available
Event History
Feb 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Advisory Published
via GitHub·03:30 AM
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-23636.
2
What is the severity level of CVE-2023-23636?
The severity level of CVE-2023-23636 is medium with a CVSS score of 5.4.
3
What is the affected software of CVE-2023-23636?
The affected software is Jellyfin version 10.8.x through 10.8.3.
4
What is the impact of CVE-2023-23636?
CVE-2023-23636 allows an attacker to steal access tokens from the localStorage of the victim.
5
How can I fix the vulnerability CVE-2023-23636?
To fix the vulnerability, update Jellyfin to a version beyond 10.8.3.