TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Collection of potential security issues in Jellyfin

1 点作者 hurutparittya大约 1 个月前

2 条评论

alabastervlog大约 1 个月前
I've been using Jellyfin for about... five years, maybe? And it would never have occurred to me to put it on the open Web. I'd never bothered to check, but I'd just assumed it was a security catastrophe, like nearly all home-user-targeted itch-scratching software is.
hurutparittya大约 1 个月前
So if I understand the last comment correctly...<p>It&#x27;s possible to get unauthenticated streams if you know the media paths. Media collections, at least in my experience, usually adhere to a few common organization schemes. This would allow someone with a list of common titles, which are available in various public databases, to leak data by brute force from a public facing Jellyfin instance quite efficiently.<p>Discounting this as merely &quot;suboptimal behavior&quot; sounds like a mistake.