PT-2023-12078 · Emby · Emby Server

·

CVE-2021-25827

·

Published

2023-06-28

·

Updated

2023-07-10

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Emby Server versions prior to 4.7.12.0
Description The issue allows for a login bypass attack by setting the X-Forwarded-For header to a local IP address. This enables unauthorized access without proper credentials.
Recommendations For versions prior to 4.7.12.0, update to version 4.7.12.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the Emby Server to minimize the risk of exploitation. Avoid using the X-Forwarded-For header in authentication processes until the issue is resolved.

Exploit

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-25827
GHSA-FFFJ-6FR6-3FGF

Affected Products

Emby Server