Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Seerr: Path traversal to RCE via /avatarproxy image cache filename from upstream ETag
Vulnerability Description
Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr's ImageProxy in server/lib/imageproxy.ts uses the upstream ETag and Content-Type response headers to build a cache filename for the unauthenticated GET /avatarproxy/:jellyfinUserId route, allowing a malicious or compromised Jellyfin or Emby server, or a man-in-the-middle attacker on a plaintext media-server connection, to supply traversal sequences that path.join and fs.writeFile normalize outside the cache directory, overwrite /app/dist/index.js or other files, and execute code as the node user after a container restart. This issue is fixed in version 3.4.0.
CVSS Information
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Seerr Team Seerr 路径遍历漏洞
Vulnerability Description
Seerr Team Seerr是Seerr Team组织开源的一个媒体资源请求管理工具。 Seerr Team Seerr 3.4.0之前版本存在安全漏洞,该漏洞源于ImageProxy使用上游ETag和Content-Type响应头构建缓存文件名,导致未经身份验证的攻击者通过路径遍历覆盖文件并在容器重启后以node用户执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A