Collection of potential security issues in Jellyfin This is a non exhaustive list of potential security issues found in Jellyfin. Some of these might cause controversy. Some of these are design fla…

  • troed@fedia.io
    link
    fedilink
    arrow-up
    85
    ·
    10 days ago

    It’s a list from 2021 and as a cybersec researcher and Jellyfin user I didn’t see anything that would make me say “do not expose Jellyfin to the Internet”.

    That’s not to say there might be something not listed, or some exploit chain using parts of this list, but at least it’s not something that has been abused over the last four years if so.

    • ilega_dh@feddit.nl
      link
      fedilink
      arrow-up
      31
      ·
      edit-2
      9 days ago

      Agreed, this is a valid list of minor concerns but this is just a fearmongering post. It’s not good that some metadata can leak but if you take normal precautions (i.e. don’t run this next to your classified information storage) it’s fine to open this so your friends can watch media.

      Source: me and my Masters degree in cybersecurity (but apparently OP just learned about Kerckhoff’s principle and rainbow tables in a completely incorrect context so I know how to do my job or smth lmao)

      Edit: lol don’t look at OPs post history, now I know where the fearmongering came from

      • ReversalHatchery@beehaw.org
        link
        fedilink
        English
        arrow-up
        3
        ·
        9 days ago

        but if you take normal precautions (i.e. don’t run this next to your classified information storage)

        oh yeah I’m pretty sure the majority of users bought a dedicated machine for Jellyfin

    • Scary le Poo@beehaw.orgOP
      link
      fedilink
      arrow-up
      21
      ·
      edit-2
      10 days ago

      The last set of comments is from 2024. These have not been addressed. The fact that it is possible to stream without auth is just bonkers.

      The entirity of jellyfin security is security via obscurity which is zero security at all.

      “As a cybersec researcher”, the limp wristed, hand wavy approach to security should be sending up alarm bells. The fact that it doesn’t, means that likely either, you don’t take your research very seriously, or you aren’t a “cybersecurity researcher”.

      “Thank you for this list. We are aware of quite a few, but for reasons of backwards compatibility they’ve never been fixed. We’d definitely like to but doing so in a non-disruptive way is the hard part.”

      Is truly one of the statements of all time.

    • ToadOfHypnosis@lemm.ee
      link
      fedilink
      English
      arrow-up
      6
      ·
      edit-2
      10 days ago

      So I have a NAS running Ubuntu I only keep my movies, my Jellyfin, and torrent software on in an isolated VLAN I stream from. I would think this would make any security issue with Jellyfin a dead end. I stream all content from Jellyfin domain I made and never use it locally. I stream off it at home from my VPN. This seems a safe way to stream where it can be used away from home unless I am missing something? Pointing out any holes in my logic is appreciated.