this post was submitted on 02 Apr 2025
208 points (100.0% liked)

Technology

38451 readers
496 users here now

A nice place to discuss rumors, happenings, innovations, and challenges in the technology sphere. We also welcome discussions on the intersections of technology and society. If it’s technological news or discussion of technology, it probably belongs here.

Remember the overriding ethos on Beehaw: Be(e) Nice. Each user you encounter here is a person, and should be treated with kindness (even if they’re wrong, or use a Linux distro you don’t like). Personal attacks will not be tolerated.

Subcommunities on Beehaw:


This community's icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.

founded 3 years ago
MODERATORS
 

Collection of potential security issues in Jellyfin This is a non exhaustive list of potential security issues found in Jellyfin. Some of these might cause controversy. Some of these are design fla...

top 50 comments
sorted by: hot top controversial new old
[–] [email protected] 9 points 11 hours ago (1 children)

Many of these have already been fixed FWIW, it's not a collection of open issues.

[–] [email protected] 6 points 9 hours ago* (last edited 9 hours ago)

No. None of the items are closed. Click the "closed" items. All of them are "Not planned. Duplicate, see 5415".

Edit: The biggest issue of unauthenticated streaming of content... https://github.com/jellyfin/jellyfin/issues/13777

Last opened last week. closed as duplicate. it's unaddressed completely.

[–] [email protected] 7 points 14 hours ago

PluginsController only requires user privileges for potentially sensitive actions

  • Includes, but is not limited to: Listing all plugins on the server without being admin, changing plugin settings, listing plugin settings without being admin. This includes the possibility of retrieving LDAP access credentials without admin privileges.

Outch

[–] [email protected] 12 points 17 hours ago* (last edited 17 hours ago) (1 children)

I remember when they were arguing that you don't need a VPN or proxy basic authentication in front of it because their team knows how to write secure code...

[–] [email protected] 6 points 14 hours ago

There's a bug (closed as won't fix) where proxy basic authentication breaks jellyfin. You can't use it.

[–] [email protected] 16 points 19 hours ago (4 children)

For those unaware, it's a good idea to be using a service like tailscale (self hosted=headscale if you don't want to make your login credentials tied to apple, google, or Microsoft). It's a VPN but a lot simpler to use.

load more comments (4 replies)
[–] [email protected] 34 points 22 hours ago (3 children)

I'm not sure who needs to hear this, but unless you work as a security engineer or in another security-focused tech field, you really shouldn't be exposing your homelab to the open internet anyway

Most people access their homelabs via VPN - i don't see anything here that's a problem for that use-case.

[–] [email protected] 3 points 14 hours ago (1 children)

I need to run a VPN already. Fine for desktop, but this isn't a solution for mobile (where you can't run two VPNs simultaneously)

[–] [email protected] 7 points 14 hours ago (2 children)

@jagged_circle @anarchiddy

It's actually possible to run 2 VPNs simultaneously on mobile using RethinkDNS which is an app available on F-Droid. For example I'm currently connected to MullvadVPN and my home network at the same time using two WireGuard configs.

[–] [email protected] 2 points 8 hours ago* (last edited 8 hours ago)

Can you order the wireguard connections?

Eg I want my connections to my home server VPN to first go through my mullvad VPN. Because I dont want any connections coming out of my device that don't go through a shared VPN or Tor.

[–] [email protected] 2 points 8 hours ago

Omg thank you!

load more comments (2 replies)
load more comments
view more: next ›