Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 904891 (CVE-2023-30626, CVE-2023-30627) - <www-apps/jellyfin-10.8.10: multiple vulnerabilities
Summary: <www-apps/jellyfin-10.8.10: multiple vulnerabilities
Status: RESOLVED FIXED
Alias: CVE-2023-30626, CVE-2023-30627
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: https://github.com/jellyfin/jellyfin/...
Whiteboard: ~1 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2023-04-23 17:49 UTC by John Helmert III
Modified: 2023-04-25 23:21 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2023-04-23 17:49:25 UTC
"CRITICAL SECURITY ADVISORY: GHSA-9p5f-5x8v-x65m and GHSA-89hp-h43h-r5pq can be combined to allow remote code execution for any authenticated Jellyfin user including non-admin users. While the particular execution mechanism of the former dates to the 10.8.0 release, the latter was present for all Jellyfin releases before this point. It is thus absolutely critical for all Jellyfin administrators, regardless of version, to upgrade to this version if they allow any untrusted users and/or expose their instance to the Internet."

Please bump to 10.8.0 ASAP.
Comment 1 Larry the Git Cow gentoo-dev 2023-04-23 18:14:36 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=716469a223ccf98b568c8bc5f9c041b80b6657d6

commit 716469a223ccf98b568c8bc5f9c041b80b6657d6
Author:     Craig Andrews <candrews@gentoo.org>
AuthorDate: 2023-04-23 18:12:34 +0000
Commit:     Craig Andrews <candrews@gentoo.org>
CommitDate: 2023-04-23 18:14:32 +0000

    www-apps/jellyfin: add 10.8.10
    
    Bug: https://bugs.gentoo.org/904891
    Signed-off-by: Craig Andrews <candrews@gentoo.org>

 www-apps/jellyfin/Manifest                |  2 +
 www-apps/jellyfin/jellyfin-10.8.10.ebuild | 67 +++++++++++++++++++++++++++++++
 2 files changed, 69 insertions(+)
Comment 2 Craig Andrews gentoo-dev 2023-04-23 18:16:45 UTC
New, fixed version added.
Old, impacted versions have been cleaned up.
Comment 3 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2023-04-25 23:21:43 UTC
Thanks! All done.