Help Net Security·3 min read·medium

Jellyfin 12.0 security fixes arrive alongside the removal of legacy client logins

A
Anamarija Pogorelec
Jellyfin 12.0 security fixes arrive alongside the removal of legacy client logins
AI Summary

Jellyfin has released version 12.0 of its media server, which includes several security patches and the removal of legacy client login support. The update also introduces stricter rules for plugin naming and improved parental controls to enhance server security.

Why it matters

These updates are critical for self-hosted media server administrators to prevent unauthorized access and mitigate potential vulnerabilities.

Dive DeeperCreate a free account to unlock

Jellyfin 12.0 security fixes arrive alongside the removal of legacy client logins Jellyfin shipped version 12.0 of its media server. Several of the security fixes in it block requests built to reach files outside the folders the server is supposed to hand out. The rest of the security work touches first-run setup, plugin installs, parental controls, and the web interface.

On a misconfigured server, someone who had not signed in could get the setup wizard, the first-run pages that create the administrator account and point Jellyfin at your libraries, to run a second time.

Plugin packages with unsafe names are now rejected. Parental controls apply in places where they previously did not, and the web client has fixes for cross-site scripting, the bug class where content an attacker supplies runs as script inside another user’s browser session.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technology

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in