CVE-2023-27161: SSRF
Jellyfin up to v10.7.7 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /Repositories. This vulnerability allows attackers to access network resources and sensitive information via a crafted POST request.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-27161.
What is the severity level of CVE-2023-27161?
CVE-2023-27161 has a severity level of 7.5, which is considered high.
How does CVE-2023-27161 affect Jellyfin?
CVE-2023-27161 affects Jellyfin versions up to v10.7.7, allowing attackers to access network resources and sensitive information through a Server-Side Request Forgery (SSRF) vulnerability in the component /Repositories.
What is the Common Weakness Enumeration (CWE) ID associated with CVE-2023-27161?
The Common Weakness Enumeration (CWE) ID associated with CVE-2023-27161 is CWE-918.
Is there a fix available for CVE-2023-27161?
It is recommended to update to a version higher than v10.7.7 to mitigate the Server-Side Request Forgery (SSRF) vulnerability in Jellyfin.