{"id":"GHSA-qwp3-5fw3-5wgv","summary":"Incorrect Access Control and Cross Site Scripting in Jellyfin","details":"In Jellyfin before 10.8, the /users endpoint has incorrect access control for admin functionality. This lack of access control can be leveraged to performe a cross site scripting attack.","aliases":["CVE-2022-35909"],"modified":"2023-11-01T04:59:23.144121Z","published":"2022-08-20T00:00:39Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-08-30T20:19:35Z","nvd_published_at":"2022-08-19T13:15:00Z","cwe_ids":["CWE-79"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-35909"},{"type":"WEB","url":"https://github.com/jellyfin/jellyfin/pull/7569/files"},{"type":"WEB","url":"https://docs.google.com/document/d/1cBXQrokCvWxKET4BKi3ZLtVp5gst6-MrGPgMKpfXw8Y/edit"},{"type":"PACKAGE","url":"https://github.com/jellyfin/jellyfin"},{"type":"WEB","url":"https://medium.com/stolabs/cve-2022-35909-cve-2022-35910-incorrect-access-control-and-xss-stored-to-jellyfin-967359c91058"}],"affected":[{"package":{"name":"Jellyfin.Common","ecosystem":"NuGet","purl":"pkg:nuget/Jellyfin.Common"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.8.0"}]}],"versions":["10.0.1","10.1.0","10.2.0","10.2.0.1","10.3.0","10.3.0-rc1","10.3.5","10.3.6","10.3.7","10.4.0","10.4.0-pre1","10.4.0-pre2","10.4.1","10.4.2","10.4.3","10.5.0","10.5.0-pre1","10.5.2","10.5.3","10.5.4","10.5.5","10.6.0","10.7.0","10.7.0-rc1","10.7.0-rc2","10.7.0-rc3","10.7.0-rc4","10.7.1","10.7.2","10.7.3","10.7.4","10.7.5","10.7.6","10.7.7","10.8.0-alpha2","10.8.0-alpha3","10.8.0-alpha4","10.8.0-alpha5","10.8.0-beta1","10.8.0-beta2","10.8.0-beta3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/08/GHSA-qwp3-5fw3-5wgv/GHSA-qwp3-5fw3-5wgv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}