.. / CVE-2021-29490

Exploit for Jellyfin 10.7.2 - Server Side Request Forgery (CVE-2021-29490)

Description:

Jellyfin is a free software media system. Versions 10.7.2 and below are vulnerable to unauthenticated Server-Side Request Forgery (SSRF) attacks via the imageUrl parameter.

Nuclei Template

View the template here CVE-2021-29490.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-29490.yaml
Copy

References:

https://github.com/Threekiii/Awesome-POC
https://github.com/ARPSyndicate/kenzer-templates
https://github.com/jellyfin/jellyfin/security/advisories/GHSA-rgjw-4fwc-9v96
https://github.com/HimmelAward/Goby_POC
https://nvd.nist.gov/vuln/detail/CVE-2021-29490