Jellyfin security issues #183

Closed
opened 2022-08-26 01:08:22 +00:00 by a · 3 comments
Owner

@ersei sent a long list of Jellyfin security issues in the exozyme #general channel https://github.com/jellyfin/jellyfin/issues/5415

Unfortunately, the LDAP credentials leakage issue is particularly serious since you can use those credentials to do some very damaging things like accessing other user accounts. For now, we will probably have to just completely disable Jellyfin until this issue is fixed.

The other issues are also bad, but not as catastrophic as this one.

One of the comments blamed this all on Emby's bad coding, so 🤷.

Since we have a long history of helping and contributing to upstream, does anyone want to try solving these issues and helping out Jellyfin? I'm pretty sure there are many other people who aren't aware of Jellyfin's poor security and are exposing it to the internet, so we could make a decent impact here.

@ersei sent a long list of Jellyfin security issues in the exozyme #general channel https://github.com/jellyfin/jellyfin/issues/5415 Unfortunately, the LDAP credentials leakage issue is particularly serious since you can use those credentials to do some very damaging things like accessing other user accounts. For now, we will probably have to just completely disable Jellyfin until this issue is fixed. The other issues are also bad, but not as catastrophic as this one. One of the comments blamed this all on Emby's bad coding, so 🤷. Since we have a long history of helping and contributing to upstream, does anyone want to try solving these issues and helping out Jellyfin? I'm pretty sure there are many other people who aren't aware of Jellyfin's poor security and are exposing it to the internet, so we could make a decent impact here.
a added this to the v9.0 milestone 2022-08-26 01:08:22 +00:00
a added the
bug
security
labels 2022-08-26 01:08:22 +00:00
a added this to the (deleted) project 2022-08-26 01:08:22 +00:00
a added a new dependency 2022-09-08 19:18:04 +00:00
Author
Owner

Closing because we discontinued Jellyfin.

Closing because we discontinued Jellyfin.
a closed this issue 2022-09-08 23:51:37 +00:00
Owner

Does upstream know of these issues? If not someone with an Github account could tell them.

Does upstream know of these issues? If not someone with an Github account could tell them.
Author
Owner

Yes, the GitHub issue linked in the top comment lists many known security vulnerabilities in Jellyfin.

Yes, the GitHub issue linked in the top comment lists many known security vulnerabilities in Jellyfin.
Sign in to join this conversation.
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Depends on
Reference: exozyme/exozyme#183
No description provided.