
本项目涉及到的仅为安全研究和授权情况下使用,其使用人员有责任和义务遵守当地法律条规。
#CVE-2021-21402 Jellyfin Arbitrary File Read
Jellyfin is a free software media system that controls and manages media and streaming. It is an alternative to Emby and Plex, delivering media from a dedicated server to end-user devices through multiple applications. Jellyfin belongs to the Emby 3.5.2 .NET Core framework to support full cross-platform capabilities.
In Jellyfin version 10.7.1, an attacker can maliciously craft a request to read arbitrary files from the Jellyfin server's file system. This issue is more prevalent when Windows is the host OS. Servers exposed to the public internet may be at risk. This issue has been fixed in version 10.7.1. The workaround is for users to restrict certain access by implementing strict security permissions on the file system.
Jellyfin < 10.7.1
Upgrade Jellyfin to the secure version (10.7.1): https://jellyfin.org/downloads/
Users can restrict certain access by implementing strict security permissions on the file system.