Piracy Social
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Mubelotix@jlai.lu to Selfhosted@lemmy.worldEnglish · 2 days ago

Jellyfin critical security update - This is not a joke

github.com

external-link
message-square
249
link
fedilink
  • cross-posted to:
  • piracy@lemmy.dbzer0.com
692
external-link

Jellyfin critical security update - This is not a joke

github.com

Mubelotix@jlai.lu to Selfhosted@lemmy.worldEnglish · 2 days ago
message-square
249
link
fedilink
  • cross-posted to:
  • piracy@lemmy.dbzer0.com
Release 10.11.7 · jellyfin/jellyfin
github.com
external-link
🚀 Jellyfin Server 10.11.7 We are pleased to announce the latest stable release of Jellyfin, version 10.11.7! This minor release brings several bugfixes to improve your Jellyfin experience. As alway...
  • JigglySackles@lemmy.world
    link
    fedilink
    English
    arrow-up
    8
    ·
    19 hours ago

    Are you singling out Jellyfin for a particular reason? Or are also going to advise just never opening ports in general?

    • kieron115@startrek.website
      link
      fedilink
      English
      arrow-up
      13
      arrow-down
      1
      ·
      edit-2
      19 hours ago

      jellyfin people just always spout this advice as some sort of copium and i dont even know why. ALL software will have security issues at some point or another. just update and move on with your life.

      • Bazoogle@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        10 hours ago

        There is a new story every week in Steve Gibson’s “Security Now” podcast about why you should virtually never open ports. And if you do, you’d better IP restrict. Even, or especially, in commercial products. Cisco has a new CVSS 10.0 every other week just about

        • kieron115@startrek.website
          link
          fedilink
          English
          arrow-up
          1
          ·
          edit-2
          10 hours ago

          I run pretty much all my stuff through NPMplus. Then I have a firewall between my public and private networks in case something does get compromised. But I’ve had Plex exposed (on a non-default port) for literally years and nothing ever happens.

          • Bazoogle@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            10 hours ago

            Why NPMplus and not the default NPM?

            • kieron115@startrek.website
              link
              fedilink
              English
              arrow-up
              2
              ·
              edit-2
              9 hours ago

              Primarily for the CrowdSec integration (one less thing to set up manually)

              https://www.virtualizationhowto.com/2025/09/nginx-proxy-manager-vs-npmplus-which-one-is-better-for-your-home-lab/

              • Bazoogle@lemmy.world
                link
                fedilink
                English
                arrow-up
                1
                ·
                8 hours ago

                Why link the fork of a fork in your original response?

                • kieron115@startrek.website
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  edit-2
                  8 hours ago

                  uhhh did i? https://github.com/ZoeyVid/NPMplus is the link I meant to post for npmplus. its a fork of npm.

      • neclimdul@lemmy.world
        link
        fedilink
        English
        arrow-up
        5
        ·
        18 hours ago

        Definitely.

        But I think more than copium it’s them understanding their users. It’s advice for people that will figure out how to run Jellyfin but won’t stay on top of updates, setup a waf, use a firewall/reverseproxy to limit access, etc. There are surely a lot of those that just one clicked an installer etc and for them it’s good advice.

        • kieron115@startrek.website
          link
          fedilink
          English
          arrow-up
          1
          ·
          17 hours ago

          that’s fair, does it not have any kind of encryption by default?

          • ℍ𝕂-𝟞𝟝@sopuli.xyz
            link
            fedilink
            English
            arrow-up
            2
            ·
            14 hours ago

            Standard TLS, I think, but what else would you need?

            • kieron115@startrek.website
              link
              fedilink
              English
              arrow-up
              1
              ·
              edit-2
              14 hours ago

              None really, just wondering what the issue with opening it up is if it has TLS? In 10+ years I’ve never had my Plex server compromised and it just uses TLS. I do change the default port but that’s it.

              • neclimdul@lemmy.world
                link
                fedilink
                English
                arrow-up
                2
                ·
                13 hours ago

                Plex logins go through their login server so you’ll also have login throttling and probably other bot protections.

                • kieron115@startrek.website
                  link
                  fedilink
                  English
                  arrow-up
                  2
                  ·
                  12 hours ago

                  They also do some SSL shenanigans to get every user a unique, valid public certificate created during setup. https://words.filippo.io/how-plex-is-doing-https-for-all-its-users/

      • JigglySackles@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        ·
        18 hours ago

        That’s kinda my perspective on it to. I mean, how do they think websites work? Gotta expose ports to make all the internet things happen. Sure commercial stuff will have more devices to protect it, but there are things you can do to mitigate issues at home too.

    • Shnog@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      arrow-down
      1
      ·
      14 hours ago

      For the vast majority of users? Yes. They shouldn’t forward ports.

      Setup a VPN gateway at Grandma’s house.

    • Possibly linux@lemmy.zip
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      1
      ·
      14 hours ago

      Jellyfin is particularly bad compared to other things. You still should avoid exposing stuff to the internet

Selfhosted@lemmy.world

selfhosted@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !selfhosted@lemmy.world

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don’t control.

Rules:

  1. Be civil: we’re here to support and learn from one another. Insults won’t be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it’s not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don’t duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

  7. No low-effort posts. This is subjective and will largely be determined by the community member reports.

Resources:

  • selfh.st Newsletter and index of selfhosted software and apps
  • awesome-selfhosted software
  • awesome-sysadmin resources
  • Self-Hosted Podcast from Jupiter Broadcasting

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 950 users / day
  • 3.43K users / week
  • 8.27K users / month
  • 9.51K users / 6 months
  • 1 local subscriber
  • 57K subscribers
  • 593 Posts
  • 8.73K Comments
  • Modlog
  • mods:
  • Ruud@lemmy.world
  • Loki@lemmy.world
  • CannaVet@lemmy.world
  • devve@lemmy.world
  • HybridSarcasm@lemmy.world
  • BE: 0.19.11
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org