CVE-2021-29490 describes an unauthenticated Server-Side Request Forgery (SSRF) vulnerability in Jellyfin versions prior to 10.7.3, allowing attackers to force the server to make requests to internal or external HTTP resources. This medium-severity vulnerability (CVSS 5.8) has a high EPSS score, indicating a significant likelihood of exploitation, and could lead to information disclosure. While there is no evidence of active exploitation or public exploit code like Metasploit or ExploitDB, Nuclei templates exist for detection. Organizations using affected Jellyfin versions should upgrade to 10.7.3 or implement the recommended workarounds to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.7.3CPE matchmatch criteria | cpe:2.3:a:jellyfin:jellyfin:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.