Collection of potential security issues in Jellyfin This is a non exhaustive list of potential security issues found in Jellyfin. Some of these might cause controversy. Some of these are design fla…

  • Saik0@lemmy.saik0.com
    link
    fedilink
    English
    arrow-up
    13
    ·
    edit-2
    17 hours ago

    With unrestricted signups, they can obtain their own account easily. With their own account they can enumerate all your other users.

    If they have their own account they can just find your instance, make a login, collect all the proof they need that you’re hosting content you don’t own (illegally own) then serve you a court summons and ruin your life.

    I wouldn’t worry about the vulnerability in the link since your already wide open. But I wouldn’t leave Jellyfin wide open either. Movie and TV studios are quite litigious.

    I hope you’re at least gatekeeping behind a vpn or something.

    Edit: typo