Jellyfin is a free software media system. Versions 10.7.2 and below are vulnerable to unauthenticated Server-Side Request Forgery (SSRF) attacks via the imageUrl parameter.
id: CVE-2021-29490
info:
name: Jellyfin 10.7.2 - Server Side Request Forgery
author: alph4byt3
...