S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2021-21402 Scanner

Detects 'Arbitrary File Read' vulnerability in Jellyfin affects v. before 10.7.1.

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.4k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
1
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-21402
6.5
CVSShigh
Exploitable remotely over the internet · low-privilege account sufficient.

Jellyfin is a Free Software Media System. In Jellyfin before version 10.7.1, with certain endpoints, well crafted requests will allow arbitrary file read from a Jellyfin server's file system. This issue is more prevalent when Windows is used as the host OS. Servers that are exposed to the public Internet are potentially at risk. This is fixed in version 10.7.1. As a workaround, users may be able to restrict some access by enforcing strict security permissions on their filesystem, however, it is recommended to update as soon as possible.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
jellyfinby jellyfin
< 10.7.1
Updated Aug 21, 2026View on NVD →
Detail

Jellyfin is a media system that allows users to access their personal media library of videos, music and photos from anywhere. It is an open-source platform that offers a wide range of customization options. With Jellyfin, users can organize their media into libraries for easy management, browse content, and even schedule live TV recordings. 

CVE-2021-21402 is a vulnerability that was detected in Jellyfin software before version 10.7.1. This vulnerability allows attackers to exploit certain endpoints to execute arbitrary file reads from the server's file system. This is especially prevalent when using Windows as the host operating system. If an attacker successfully exploits this vulnerability, they could potentially access sensitive data, including personal information, financial data, or confidential documents.

Exploiting the CVE-2021-21402 vulnerability in Jellyfin can lead to significant consequences. With file system access, attackers can read sensitive data, modify files or even delete them, causing data loss or permanent damage to the system. In addition, this vulnerability can be exploited to gain further access to the compromised system, allowing attackers to conduct more significant attacks, including espionage or stealing of sensitive data.

In conclusion, digital asset security is of utmost importance in the technological age we live in. By leveraging the powerful security features of platforms like s4e.io, individuals and businesses can quickly and easily learn about vulnerabilities in their digital assets and take action to protect them. With such tools, the potential risks of vulnerabilities like CVE-2021-21402 can be effectively mitigated.

 

REFERENCES

Solution Advice

To protect against the CVE-2021-21402 vulnerability in Jellyfin, users are advised to take the following precautions:

  • Update to the latest version of Jellyfin (version 10.7.1 or later).
  • Restrict access to their Jellyfin server by enforcing strict security permissions on their file system.
  • Run Jellyfin on a separate, isolated system to minimize the potential impact of a successful attack.
  • Use a firewall to block incoming traffic on ports that are not required for Jellyfin to function.
  • Monitor for any suspicious activity on their Jellyfin server, including file system changes or unexpected logins.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.