github.com
https://github.com/jellyfin/jellyfin CVE-2023-30626
HIGH
Jellyfin vulnerable to directory traversal and file write causing arbitrary code execution
Record summary
CVE-2023-30626 has a selected CVSS score of 8.8 (high).
Description
Jellyfin is a free-software media system. Versions starting with 10.8.0 and prior to 10.8.10 and prior have a directory traversal vulnerability inside the `ClientLogController`, specifically `/ClientLog/Document`. When combined with a cross-site scripting vulnerability (CVE-2023-30627), this can result in file write and arbitrary code execution. Version 10.8.10 has a patch for this issue. There are no known workarounds.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 3, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
jellyfinBrowse jellyfin / jellyfin | CVE List | >= 10.8.0, < 10.8.10 | affected |
Jellyfin.ControllerBrowse NuGet / Jellyfin.Controller | GitHub Advisory | 10.8.0 to < 10.8.10 · Fixed in 10.8.10 | affected |
References
8github.com
https://github.com/jellyfin/jellyfin-web/security/advisories/GHSA-89hp-h43h-r5pq github.com
https://github.com/jellyfin/jellyfin/blob/22d880662283980dec994cd7d35fe269613bfce3/Jellyfin.Api/Controllers/ClientLogController.cs github.com
https://github.com/jellyfin/jellyfin/commit/82ad2633fdfb1c37a158057c7935f83e1129eda7 github.com
https://github.com/jellyfin/jellyfin/pull/5918 github.com
https://github.com/jellyfin/jellyfin/releases/tag/v10.8.10 github.comConfirmation
https://github.com/jellyfin/jellyfin/security/advisories/GHSA-9p5f-5x8v-x65m nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-30626