this post was submitted on 02 Apr 2025
215 points (100.0% liked)

Technology

38432 readers
479 users here now

A nice place to discuss rumors, happenings, innovations, and challenges in the technology sphere. We also welcome discussions on the intersections of technology and society. If it’s technological news or discussion of technology, it probably belongs here.

Remember the overriding ethos on Beehaw: Be(e) Nice. Each user you encounter here is a person, and should be treated with kindness (even if they’re wrong, or use a Linux distro you don’t like). Personal attacks will not be tolerated.

Subcommunities on Beehaw:


This community's icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.

founded 3 years ago
MODERATORS
 

Collection of potential security issues in Jellyfin This is a non exhaustive list of potential security issues found in Jellyfin. Some of these might cause controversy. Some of these are design fla...

top 50 comments
sorted by: hot top controversial new old
[–] ipkpjersi@lemmy.ml 13 points 14 hours ago* (last edited 1 hour ago) (1 children)

~~Many of these have already been fixed FWIW, it's not a collection of open issues.~~ Nevermind, they have only been closed, not fixed. Yikes.

[–] Saik0Shinigami@lemmy.saik0.com 11 points 12 hours ago* (last edited 12 hours ago) (1 children)

No. None of the items are closed. Click the "closed" items. All of them are "Not planned. Duplicate, see 5415".

Edit: The biggest issue of unauthenticated streaming of content... https://github.com/jellyfin/jellyfin/issues/13777

Last opened last week. closed as duplicate. it's unaddressed completely.

[–] ipkpjersi@lemmy.ml 1 points 1 hour ago

That's really sad. Damn, how disappointing.

[–] jagged_circle@feddit.nl 9 points 17 hours ago

PluginsController only requires user privileges for potentially sensitive actions

  • Includes, but is not limited to: Listing all plugins on the server without being admin, changing plugin settings, listing plugin settings without being admin. This includes the possibility of retrieving LDAP access credentials without admin privileges.

Outch

[–] ReversalHatchery@beehaw.org 15 points 20 hours ago* (last edited 20 hours ago) (1 children)

I remember when they were arguing that you don't need a VPN or proxy basic authentication in front of it because their team knows how to write secure code...

[–] jagged_circle@feddit.nl 8 points 18 hours ago

There's a bug (closed as won't fix) where proxy basic authentication breaks jellyfin. You can't use it.

[–] easily3667@lemmus.org 19 points 22 hours ago (1 children)

For those unaware, it's a good idea to be using a service like tailscale (self hosted=headscale if you don't want to make your login credentials tied to apple, google, or Microsoft). It's a VPN but a lot simpler to use.

[–] jagged_circle@feddit.nl 4 points 18 hours ago (1 children)

I dont know what that means.

Can I use that in addition to another VPN on mobile?

[–] easily3667@lemmus.org 2 points 15 hours ago (1 children)

Afaik android doesn't allow two VPNs at the same time. If you have a VPN back to your home already, like via your router, you don't need tailscale although I'd argue it's still better.

If you mean a VPN like mullvad, afaik you can't mullvad and tailscale at the same time. I may be wrong but I gave up on global VPNs a while ago.

[–] Laristal@lemmy.dbzer0.com 3 points 12 hours ago (1 children)

You can, its an option if you use tailscale. https://tailscale.com/mullvad

Also look into using tailscale lock to secure things more if you do decide to use it

[–] easily3667@lemmus.org 1 points 10 hours ago

Oh right I forgot about that, cool. Should see if you can do this with headscale (ie client feature vs server feature)

[–] anarchiddy@lemmy.dbzer0.com 40 points 1 day ago (6 children)

I'm not sure who needs to hear this, but unless you work as a security engineer or in another security-focused tech field, you really shouldn't be exposing your homelab to the open internet anyway

Most people access their homelabs via VPN - i don't see anything here that's a problem for that use-case.

load more comments (6 replies)
load more comments
view more: next ›