GHSL-2023-028: Remote Code Execution in jellyfin - CVE-2023-48702
Published Dec 13, 2023
·Updated
A user with administrator permissions is able to run arbitrary code on the jellyfin server via the /System/MediaEncoder/Path endpoint.
Affected Software
1 affected component
Jellyfin Jellyfin
Event History
Dec 13, 2023
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of GHSL-2023-028?
The severity of GHSL-2023-028 is rated at 55, indicating a significant risk level.
2
How do I fix GHSL-2023-028?
To fix GHSL-2023-028, it is recommended to update Jellyfin to version 10.8.13 or later.
3
What are the potential impacts of GHSL-2023-028?
The potential impacts of GHSL-2023-028 include the ability for an attacker with administrator permissions to execute arbitrary code on the Jellyfin server.
4
Who is affected by GHSL-2023-028?
GHSL-2023-028 affects users of Jellyfin who have administrator permissions.
5
When was GHSL-2023-028 published?
GHSL-2023-028 was published on December 13, 2023.