• Login
  • Register
  • Login Register
    Login
    Username/Email:
    Password:
    Or login with a social network below
  • Forum
  • Website
  • GitHub
  • Status
  • Translation
  • Features
  • Team
  • Rules
  • Help
  • Feeds
User Links
  • Login
  • Register
  • Login Register
    Login
    Username/Email:
    Password:
    Or login with a social network below

    Useful Links Forum Website GitHub Status Translation Features Team Rules Help Feeds
    Jellyfin Forum Support General Questions [Help Needed] How to prevent anonymous access to resources(poster) on Jellyfin server

     
    • 0 Vote(s) - 0 Average

    [Help Needed] How to prevent anonymous access to resources(poster) on Jellyfin server

    TheDreadPirate
    Offline

    Community Moderator

    Posts: 15,374
    Threads: 10
    Joined: 2023 Jun
    Reputation: 460
    Country:United States
    #6
    2024-10-14, 04:26 PM
    Ah. Posters. I had it in my head you were talking about the actual media. Reading comprehension fail.

    That is the current behavior, yes. It is a known issue that requires a significant rework of how images are served.

    Here is the github issue that is a sort of "collection of known security issues".

    https://github.com/jellyfin/jellyfin/issues/5415

    Most are relatively minor. The team has addressed more severe security issues when disclosed, such as privilege escalation vulnerabilities, and unauthenticated access to media.

    Some ways to mitigate risk are the following.

    1) Hide user names from the login screen (default behavior now, IIRC)
    2) Use a reverse proxy and https instead of directly exposing Jellyfin to the Internet
    3) Setup fail2ban for both Jellyfin and your reverse proxy to ban repeated login/access failures
    Jellyfin 10.10.7 (Docker)
    Ubuntu 24.04.2 LTS w/HWE
    Intel i3 12100
    Intel Arc A380
    OS drive - SK Hynix P41 1TB
    Storage
        4x WD Red Pro 6TB CMR in RAIDZ1
    [Image: GitHub%20Sponsors-grey?logo=github]
    « Next Oldest | Next Newest »

    Users browsing this thread: 1 Guest(s)


    Messages In This Thread
    [Help Needed] How to prevent anonymous access to resources(poster) on Jellyfin server - by nikoinfo - 2024-10-07, 10:39 AM
    RE: [Help Needed] How to prevent anonymous access to resources(poster) on Jellyfin server - by TheDreadPirate - 2024-10-07, 12:46 PM
    RE: [Help Needed] How to prevent anonymous access to resources(poster) on Jellyfin server - by nikoinfo - 2024-10-12, 05:24 AM
    RE: [Help Needed] How to prevent anonymous access to resources(poster) on Jellyfin server - by TheDreadPirate - 2024-10-13, 01:19 AM
    RE: [Help Needed] How to prevent anonymous access to resources(poster) on Jellyfin server - by nikoinfo - 2024-10-14, 12:17 PM
    RE: [Help Needed] How to prevent anonymous access to resources(poster) on Jellyfin server - by TheDreadPirate - 2024-10-14, 04:26 PM
    RE: [Help Needed] How to prevent anonymous access to resources(poster) on Jellyfin server - by nikoinfo - 2024-10-15, 02:07 AM

    • View a Printable Version
    • Subscribe to this thread
    Forum Jump:

    Home · Team · Help · Contact
    © Designed by D&D - Powered by MyBB
    L


    Jellyfin

    The Free Software Media System

    Linear Mode
    Threaded Mode