Christian Lemmy
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Mubelotix@jlai.lu to Selfhosted@lemmy.worldEnglish · 16 hours ago

Jellyfin critical security update - This is not a joke

github.com

external-link
message-square
112
link
fedilink
  • cross-posted to:
  • piracy@lemmy.dbzer0.com
0
external-link

Jellyfin critical security update - This is not a joke

github.com

Mubelotix@jlai.lu to Selfhosted@lemmy.worldEnglish · 16 hours ago
message-square
112
link
fedilink
  • cross-posted to:
  • piracy@lemmy.dbzer0.com
Release 10.11.7 · jellyfin/jellyfin
github.com
external-link
🚀 Jellyfin Server 10.11.7 We are pleased to announce the latest stable release of Jellyfin, version 10.11.7! This minor release brings several bugfixes to improve your Jellyfin experience. As alway...
  • varnia@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    0
    ·
    14 hours ago

    There is a good reason I only have Jellyfin and other services accessible via valid Client Certificate.

    • sudoMakeUser@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      0
      ·
      11 hours ago

      Also interested how this works for mobile apps. I self host a number of services through caddy as my reverse proxy but each application is just dependent on it’s own authentication. If I exposed all my services to the internet, that’s a huge attack vector. If anyone else has some ideas I’d be happy to listen.

      • daniskarma@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        0
        ·
        5 hours ago

        If you are the only user and don’t need to use those apps in devices you don’t own a vpn is the way to go.

        If not. Depending the number of users you could do some heavy ip geoblocking to at least reduce the exposed surface.

        There are a few services I have just like 3 IPs allowed to get a response from caddy, any other ip gets 403 error.

    • daniskarma@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      0
      ·
      11 hours ago

      Does it work with android and TV apps?

      I tried long ago and failed.

      • varnia@lemmy.blahaj.zone
        link
        fedilink
        English
        arrow-up
        0
        ·
        10 hours ago

        No, we only use Jellyfin via browser. Unfortunately even with imported Client Cert, Android apps won’t work.

        Edit: Client Certs need to be implemented per App. There is a feature request from 2022 https://features.jellyfin.org/posts/1461/capability-to-specify-client-certificate-for-android-client

        • greyscale@lemmy.grey.ooo
          link
          fedilink
          English
          arrow-up
          0
          ·
          5 hours ago

          > No, we only use Jellyfin via browser.

Selfhosted@lemmy.world

selfhosted@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !selfhosted@lemmy.world

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don’t control.

Rules:

  1. Be civil: we’re here to support and learn from one another. Insults won’t be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it’s not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don’t duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

  7. No low-effort posts. This is subjective and will largely be determined by the community member reports.

Resources:

  • selfh.st Newsletter and index of selfhosted software and apps
  • awesome-selfhosted software
  • awesome-sysadmin resources
  • Self-Hosted Podcast from Jupiter Broadcasting

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 128 users / day
  • 426 users / week
  • 1.82K users / month
  • 2.12K users / 6 months
  • 0 local subscribers
  • 58K subscribers
  • 508 Posts
  • 6.12K Comments
  • Modlog
  • mods:
  • Ruud@lemmy.world
  • Loki@lemmy.world
  • CannaVet@lemmy.world
  • devve@lemmy.world
  • HybridSarcasm@lemmy.world
  • UI: unknown version
  • BE: 0.19.13
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org