Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestion detail

Untriaged
updated 2 weeks, 4 days ago by @florentc Activity log
  • Created automatic suggestion
  • @florentc deleted
    2 maintainers
    • @mweinelt
    • @dotlambda
    maintainer.delete
  • @florentc added
    2 maintainers
    • @mweinelt
    • @dotlambda
    maintainer.add
Tautulli: Unauthenticated Path Traversal in `/newsletter/image/images` endpoint

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /newsletter/image/images API endpoint is vulnerable to path traversal, allowing unauthenticated attackers to read arbitrary files from the application server's filesystem. This issue has been patched in version 2.17.0.

Affected products

Tautulli
  • ==< 2.17.0

Matching in nixpkgs

pkgs.tautulli

Python based monitoring and tracking tool for Plex Media Server

Package maintainers