VYPR
Medium severity5.8NVD Advisory· Published May 6, 2021· Updated Jun 17, 2026

CVE-2021-29490

CVE-2021-29490

Description

Jellyfin is a free software media system that provides media from a dedicated server to end-user devices via multiple apps. Verions prior to 10.7.3 vulnerable to unauthenticated Server-Side Request Forgery (SSRF) attacks via the imageUrl parameter. This issue potentially exposes both internal and external HTTP servers or other resources available via HTTP GET that are visible from the Jellyfin server. The vulnerability is patched in version 10.7.3. As a workaround, disable external access to the API endpoints /Items/*/RemoteImages/Download, /Items/RemoteSearch/Image and /Images/Remote via reverse proxy, or limit to known-friendly IPs.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Jellyfin/Jellyfin3 versions
    cpe:2.3:a:jellyfin:jellyfin:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:jellyfin:jellyfin:*:*:*:*:*:*:*:*range: <10.7.3
    • (no CPE)range: <10.7.3
    • (no CPE)range: <= 10.7.2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.