tomateaux mutters.
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Mubelotix@jlai.lu to Selfhosted@lemmy.worldEnglish · 3 days ago

Jellyfin critical security update - This is not a joke

github.com

external-link
message-square
250
link
fedilink
691
external-link

Jellyfin critical security update - This is not a joke

github.com

Mubelotix@jlai.lu to Selfhosted@lemmy.worldEnglish · 3 days ago
message-square
250
link
fedilink
Release 10.11.7 · jellyfin/jellyfin
github.com
external-link
🚀 Jellyfin Server 10.11.7 We are pleased to announce the latest stable release of Jellyfin, version 10.11.7! This minor release brings several bugfixes to improve your Jellyfin experience. As alway...
  • kieron115@startrek.website
    link
    fedilink
    English
    arrow-up
    13
    arrow-down
    1
    ·
    edit-2
    1 day ago

    jellyfin people just always spout this advice as some sort of copium and i dont even know why. ALL software will have security issues at some point or another. just update and move on with your life.

    • neclimdul@lemmy.world
      link
      fedilink
      English
      arrow-up
      5
      ·
      1 day ago

      Definitely.

      But I think more than copium it’s them understanding their users. It’s advice for people that will figure out how to run Jellyfin but won’t stay on top of updates, setup a waf, use a firewall/reverseproxy to limit access, etc. There are surely a lot of those that just one clicked an installer etc and for them it’s good advice.

      • kieron115@startrek.website
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 day ago

        that’s fair, does it not have any kind of encryption by default?

        • ℍ𝕂-𝟞𝟝@sopuli.xyz
          link
          fedilink
          English
          arrow-up
          2
          ·
          1 day ago

          Standard TLS, I think, but what else would you need?

          • kieron115@startrek.website
            link
            fedilink
            English
            arrow-up
            1
            ·
            edit-2
            1 day ago

            None really, just wondering what the issue with opening it up is if it has TLS? In 10+ years I’ve never had my Plex server compromised and it just uses TLS. I do change the default port but that’s it.

            • neclimdul@lemmy.world
              link
              fedilink
              English
              arrow-up
              2
              ·
              1 day ago

              Plex logins go through their login server so you’ll also have login throttling and probably other bot protections.

              • kieron115@startrek.website
                link
                fedilink
                English
                arrow-up
                2
                ·
                24 hours ago

                They also do some SSL shenanigans to get every user a unique, valid public certificate created during setup. https://words.filippo.io/how-plex-is-doing-https-for-all-its-users/

    • Bazoogle@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      22 hours ago

      There is a new story every week in Steve Gibson’s “Security Now” podcast about why you should virtually never open ports. And if you do, you’d better IP restrict. Even, or especially, in commercial products. Cisco has a new CVSS 10.0 every other week just about

      • kieron115@startrek.website
        link
        fedilink
        English
        arrow-up
        1
        ·
        edit-2
        21 hours ago

        I run pretty much all my stuff through NPMplus. Then I have a firewall between my public and private networks in case something does get compromised. But I’ve had Plex exposed (on a non-default port) for literally years and nothing ever happens.

        • Bazoogle@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          21 hours ago

          Why NPMplus and not the default NPM?

          • kieron115@startrek.website
            link
            fedilink
            English
            arrow-up
            2
            ·
            edit-2
            21 hours ago

            Primarily for the CrowdSec integration (one less thing to set up manually)

            https://www.virtualizationhowto.com/2025/09/nginx-proxy-manager-vs-npmplus-which-one-is-better-for-your-home-lab/

            • Bazoogle@lemmy.world
              link
              fedilink
              English
              arrow-up
              1
              ·
              20 hours ago

              Why link the fork of a fork in your original response?

              • kieron115@startrek.website
                link
                fedilink
                English
                arrow-up
                1
                ·
                edit-2
                19 hours ago

                uhhh did i? https://github.com/ZoeyVid/NPMplus is the link I meant to post for npmplus. its a community fork of npm.

    • JigglySackles@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      ·
      1 day ago

      That’s kinda my perspective on it to. I mean, how do they think websites work? Gotta expose ports to make all the internet things happen. Sure commercial stuff will have more devices to protect it, but there are things you can do to mitigate issues at home too.

Selfhosted@lemmy.world

selfhosted@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don’t control.

Rules:

  1. Be civil: we’re here to support and learn from one another. Insults won’t be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it’s not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don’t duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

  7. No low-effort posts. This is subjective and will largely be determined by the community member reports.

Resources:

  • selfh.st Newsletter and index of selfhosted software and apps
  • awesome-selfhosted software
  • awesome-sysadmin resources
  • Self-Hosted Podcast from Jupiter Broadcasting

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 808 users / day
  • 3.47K users / week
  • 8.22K users / month
  • 16.5K users / 6 months
  • 1 local subscriber
  • 57K subscribers
  • 2.24K Posts
  • 46.7K Comments
  • Modlog
  • mods:
  • Ruud@lemmy.world
  • Loki@lemmy.world
  • CannaVet@lemmy.world
  • devve@lemmy.world
  • HybridSarcasm@lemmy.world
  • HybridSarcasm@lemmy.hybridsarcasm.xyz
  • BE: 0.19.11
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org