漏洞描述 Jellyfin是一个免费软件媒体系统。在10.7.1版之前的Jellyfin中,带有某些终结点的精心设计的请求将允许从Jellyfin服务器的文件系统中读取任意文件。当Windows用作主机OS时,此问题更为普遍。
相关漏洞推荐 CVE-2021-21402: Jellyfin <10.7.0 - Local File Inclusion POC 2025-08-01 | Jellyfin Jellyfin before 10.7.0 is vulnerable to local file inclusion. This issue is more prevalent when Wind... CVE-2021-29490: Jellyfin 10.7.2 - Server Side Request Forgery POC 2025-08-01 | Jellyfin Jellyfin is a free software media system. Versions 10.7.2 and below are vulnerable to unauthenticate... Jellyfin RemoteImageController.cs SSRF漏洞(CVE-2021-29490) 无POC 2021-12-09 | Jellyfin Jellyfin是一个免费软件媒体系统。Jellyfin RemoteImageController.cs文件中存在SSRF漏洞,通过构造特殊的请求,探测内网信息 ShowDoc /server/index.php?s=/api/adminUpdate/download 文件上传漏洞(CVE-2021-36440) 无POC 2025-09-12 | ShowDoc ShowDoc 2.9.5版本存在一个高危的文件上传漏洞(CVE-2021-36440),该漏洞源于系统未能对上传文件的类型进行充分验证。攻击者可以绕过安全限制上传任意类型的危险文件,包括但不限于PH... CVE-2021-1497: Cisco HyperFlex HX Data Platform - Remote Command Execution POC 2025-09-01 | Cisco HyperFlex HX Data Platform Cisco HyperFlex HX contains multiple vulnerabilities in the web-based management interface that coul...