← Back to context

Comment by Mashimo

14 hours ago

He claims there are known exploits. Though I also want to know if this is really true.

https://github.com/jellyfin/jellyfin/issues/5415

  • The absolute worst thing I can see in there is that an third party who somehow managed to get a link to one of your library items (either directly from you or from one of your users--or by spending the next decade bruteforcing it I guess) could stream said item: https://github.com/jellyfin/jellyfin/issues/5415#issuecommen...

    Everything else looks to me like unimportant issues, that would provide someone who's already logged in as a user minor details about your server.