Collection of potential security issues in Jellyfin This is a non exhaustive list of potential security issues found in Jellyfin. Some of these might cause controversy. Some of these are design fla…

  • 𝓔𝓶𝓶𝓲𝓮@lemm.ee
    cake
    link
    fedilink
    arrow-up
    0
    ·
    edit-2
    11 days ago

    I think you can IP whitelist who can access it no? That should solve any problems

    There is zero (0) chance of an attacker to know and then spoof address of your friend unless you have even bigger problems. Good filter should simply not respond to any packets making very existence of exploitable site undetectable.

    • jherazob@beehaw.org
      link
      fedilink
      English
      arrow-up
      1
      ·
      10 days ago

      Wrong use case, the expected one is friends and family watching stuff on your Jellyfin server from different homes, potentially through mobile, all with dynamic IPs

          • unbuckled@lemm.ee
            link
            fedilink
            arrow-up
            1
            ·
            10 days ago

            You would set up the allowlist in your firewall. There are plenty of free options for dynamic DNS though not from any ISPs that I’m aware of.

            • ReversalHatchery@beehaw.org
              link
              fedilink
              English
              arrow-up
              1
              ·
              10 days ago

              oh, in your firewall. I think I can count the percents on one hand about how much of jellyfin users run a firewall applience besides it