# Security: Regarding CVE-2018-21031

**URL:** https://forums.plex.tv/t/security-regarding-cve-2018-21031/493286
**Category:** Announcements
**Tags:** security-notices
**Created:** [November 19, 2019, 7:31pm UTC](https://forums.plex.tv/t/security-regarding-cve-2018-21031/493286 "2019-11-19T19:31:13Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![PlexSecurity](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/plexsecurity/32/160328_2.png) [@PlexSecurity](https://forums.plex.tv/u/PlexSecurity)
#### Post date: [November 19, 2019, 7:31pm UTC](https://forums.plex.tv/t/security-regarding-cve-2018-21031/493286/1 "2019-11-19T19:31:13Z")

</div>

Hello!

Yesterday we were notified that [CVE-2018-21031](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-21031) was filed against the Plex Media Server and we wanted to address that in this post.

The issue described in CVE-2018-21031 is not a vulnerability in Plex Media Server. The article and video referenced in the CVE demonstrate a way that an attacker can exploit a common misconfiguration of a piece of third-party software (Tautulli) to obtain a Plex authentication token.

Once in possession of this token, the attacker is indistinguishable from the legitimate user, and can access the Plex Media Server. This does not reflect an issue with any Plex product. Users who authenticate with third-party software to Plex are advised to ensure that that software does not expose authentication tokens to the public internet. For instance, in Tautulli it’s recommended that you require authentication to access the tool.

Stay safe out there!

Thanks,  
Plex Security Team

---

<div class="post-metadata">

### Author: ![PlexSecurity](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/plexsecurity/32/160328_2.png) [@PlexSecurity](https://forums.plex.tv/u/PlexSecurity)
#### Post date: [November 19, 2019, 7:31pm UTC](https://forums.plex.tv/t/security-regarding-cve-2018-21031/493286/2 "2019-11-19T19:31:51Z")

</div>


