Mubelotix@jlai.lu to Selfhosted@lemmy.worldEnglish · 1 day agoJellyfin critical security update - This is not a jokegithub.comexternal-linkmessage-square133linkfedilinkarrow-up11 cross-posted to: piracy@lemmy.dbzer0.com
arrow-up11external-linkJellyfin critical security update - This is not a jokegithub.comMubelotix@jlai.lu to Selfhosted@lemmy.worldEnglish · 1 day agomessage-square133linkfedilink cross-posted to: piracy@lemmy.dbzer0.com
minus-squareatzanteol@sh.itjust.workslinkfedilinkEnglisharrow-up0·22 hours agoY’all are assuming the security issue is something exploitable without authentication or has something to do with auth. But it sounds like a supply chain issue which a VPN won’t protect you from.
minus-squareWhyJiffie@sh.itjust.workslinkfedilinkEnglisharrow-up0·4 hours agoto be fair, Jellyfin had multiple unauthenticated vulnerabilities in the past so it makes sense to talk about it
Y’all are assuming the security issue is something exploitable without authentication or has something to do with auth.
But it sounds like a supply chain issue which a VPN won’t protect you from.
to be fair, Jellyfin had multiple unauthenticated vulnerabilities in the past so it makes sense to talk about it