• Login
  • Register
  • Login Register
    Login
    Username/Email:
    Password:
    Or login with a social network below
  • Forum
  • Website
  • GitHub
  • Status
  • Translation
  • Features
  • Team
  • Rules
  • Help
  • Feeds
User Links
  • Login
  • Register
  • Login Register
    Login
    Username/Email:
    Password:
    Or login with a social network below

    Useful Links Forum Website GitHub Status Translation Features Team Rules Help Feeds
    Jellyfin Forum Development Web Development Vulnerabilities found in the web interface

     
    • 0 Vote(s) - 0 Average

    Vulnerabilities found in the web interface

    thornbill
    Offline

    Core Team

    Posts: 177
    Threads: 6
    Joined: 2023 Jun
    Reputation: 8
    Country:United States
    #2
    2023-06-23, 07:32 PM
    My initial thoughts are:

    1. CSRF tokens would be good to add, but probably a lower priority than some of the other known issues atm. (This will require a coordinated effort between server and web.)
    2. Our reverse proxy documentation does cover adding CSP headers, and we are somewhat limited with what we can add to avoid breaking apps that bundle or wrap the web interface, but we could probably ship some less strict defaults. (This would largely fall on the server side to implement.) There are a couple existing issues and feature requests that are tracking this.
    3. This one looks like a false positive. It seemed to pickup some of our help text for adding server urls as hardcoded IP addresses. We've seen similar false reports for version number checks that use four digits (i.e. 3.4.1.2).
    1
    1
    « Next Oldest | Next Newest »

    Users browsing this thread: 1 Guest(s)


    Messages In This Thread
    Vulnerabilities found in the web interface - by gaming09 - 2023-06-23, 04:57 PM
    RE: Vulnerabilities found in the web interface - by thornbill - 2023-06-23, 07:32 PM
    RE: Vulnerabilities found in the web interface - by gaming09 - 2023-06-23, 07:55 PM

    • View a Printable Version
    • Subscribe to this thread
    Forum Jump:

    Home · Team · Help · Contact
    © Designed by D&D - Powered by MyBB
    L


    Jellyfin

    The Free Software Media System

    Linear Mode
    Threaded Mode