vendor:
Emby MediaServer
by:
Unknown
4
CVSS
MEDIUM
Directory Traversal File Disclosure
22
CWE
Product Name: Emby MediaServer
Affected Version From: 3.0.0
Affected Version To: 3.2.2005
Patch Exists: NO
Related CWE: Unknown
CPE: a:emby_llc:emby_mediaserver
Platforms Tested: Windows, Linux, Mac
Unknown
Emby MediaServer 3.2.5 Directory Traversal File Disclosure Vulnerability
The vulnerability allows an attacker to disclose the contents of arbitrary files via directory traversal attacks. The issue exists in the 'swagger-ui' object in SwaggerService.cs file. Input passed to this object is not properly verified before being used to load resources. The vulnerability affects multiple versions of Emby MediaServer, with different affected platforms for each version.
Mitigation:
Apply the vendor's patches as they become available. Restrict access to the affected application from untrusted networks or users.