• Login
  • Register
  • Login Register
    Login
    Username/Email:
    Password:
    Or login with a social network below
  • Forum
  • Website
  • GitHub
  • Status
  • Translation
  • Features
  • Team
  • Rules
  • Help
  • Feeds
User Links
  • Login
  • Register
  • Login Register
    Login
    Username/Email:
    Password:
    Or login with a social network below

    Useful Links Forum Website GitHub Status Translation Features Team Rules Help Feeds
    Jellyfin Forum Announcements Project Announcements New Server/Web Hotfix Release: 10.8.13

     
    • 0 Vote(s) - 0 Average

    New Server/Web Hotfix Release: 10.8.13

    Stable 10.8.z hotfix release
    joshuaboniface
    Offline

    Project Leader

    Posts: 115
    Threads: 25
    Joined: 2023 Jun
    Reputation: 16
    Country:Canada
    #1
    2023-11-29, 04:14 AM (This post was last modified: 2023-12-06, 05:33 AM by joshuaboniface. Edited 6 times in total.)
    We're pleased to announce a new hotfix release for the Jellyfin server and web client, 10.8.13!

    This release mainly focuses on two major security vulnerabilities found over the previous couple weeks, as well as a few minor bugfixes. We strongly recommend that all users update to this release as soon as possible, as the details of these vulnerabilities will be made public on December 5th 2023 (and one of them is quite a doozie).

    This release does make a functional change to Jellyfin: with this version, you are now unable to edit the FFmpeg binary path in the Jellyfin WebUI. This has been done for security reasons, the full reasoning for which as well as some reminders for all Jellyfin administrators can be found in our new blog post over on the main website.

    10.8.13 should be a seamless upgrade, but of course if you notice any problems please open a thread in the Troubleshooting forum for assistance!

    The release on GitHub, including changelog, is at: https://github.com/jellyfin/jellyfin/rel...g/v10.8.13

    Binaries are available in all the usual places: Docker Hub, Our Official OS Repos, and Our Main Repository Page. MacOS and Windows installers will be available shortly are up (someone always asks; they're a manual process that must be done by Anthony after the main builds finish and usually take ~1 hour  to complete Winking-face).

    Happy watching!

    EDIT 2023-11-29 17:00 EST: Due to a regression in our Jellyfin FFmpeg (https://github.com/jellyfin/jellyfin/issues/10654), we've pushed a new combined Docker image at version 10.8.13-1. All the server and web code is identical, it just has the updated jellyfin-ffmpeg package included. latest has been updated to match.

    EDIT 2023-12-06 00:31 EST: The GHSA advisories for the two aforementioned security issues have been published as "Possible Remote Code Execution via custom FFmpeg binary" (CVE-2023-48702) and "Argument Injection in FFmpeg codec parameters" (CVE-2023-49096).
    2
    2
    1
    1
    « Next Oldest | Next Newest »

    Users browsing this thread: 1 Guest(s)


    Messages In This Thread
    New Server/Web Hotfix Release: 10.8.13 - by joshuaboniface - 2023-11-29, 04:14 AM
    RE: New Server/Web Hotfix Release: 10.8.13 - by crobibero - 2023-11-29, 04:40 AM
    RE: New Server/Web Hotfix Release: 10.8.13 - by Connected3809 - 2023-11-29, 05:26 AM
    RE: New Server/Web Hotfix Release: 10.8.13 - by anthonylavado - 2023-11-29, 05:52 AM
    RE: New Server/Web Hotfix Release: 10.8.13 - by paulc - 2023-11-29, 06:11 AM
    RE: New Server/Web Hotfix Release: 10.8.13 - by Connected3809 - 2023-11-29, 02:53 PM
    RE: New Server/Web Hotfix Release: 10.8.13 - by joshuaboniface - 2023-11-29, 09:58 PM
    RE: New Server/Web Hotfix Release: 10.8.13 - by vitalessandro - 2023-11-29, 01:45 PM
    RE: New Server/Web Hotfix Release: 10.8.13 - by TaliaDias - 2023-11-29, 08:59 PM
    RE: New Server/Web Hotfix Release: 10.8.13 - by anthonylavado - 2023-11-29, 10:07 PM
    RE: New Server/Web Hotfix Release: 10.8.13 - by Representing_all_cats - 2023-11-30, 02:05 AM
    RE: New Server/Web Hotfix Release: 10.8.13 - by I-G-1-1 - 2023-12-01, 05:02 PM
    RE: New Server/Web Hotfix Release: 10.8.13 - by tmsrxzar - 2023-12-01, 05:34 PM
    RE: New Server/Web Hotfix Release: 10.8.13 - by I-G-1-1 - 2023-12-01, 06:24 PM
    RE: New Server/Web Hotfix Release: 10.8.13 - by pixel24 - 2023-12-05, 10:54 AM
    RE: New Server/Web Hotfix Release: 10.8.13 - by niels - 2023-12-05, 11:04 AM
    RE: New Server/Web Hotfix Release: 10.8.13 - by pixel24 - 2023-12-05, 11:13 AM
    RE: New Server/Web Hotfix Release: 10.8.13 - by MegaUltraGigaChad - 2023-12-05, 07:54 PM
    RE: New Server/Web Hotfix Release: 10.8.13 - by FireSale - 2023-12-05, 11:37 PM
    RE: New Server/Web Hotfix Release: 10.8.13 - by joshuaboniface - 2023-12-06, 05:29 AM
    RE: New Server/Web Hotfix Release: 10.8.13 - by tmsrxzar - 2023-12-06, 02:30 PM
    RE: New Server/Web Hotfix Release: 10.8.13 - by Perseverant - 2023-12-20, 02:22 AM
    RE: New Server/Web Hotfix Release: 10.8.13 - by JasonThai - 2024-02-15, 01:09 AM
    RE: New Server/Web Hotfix Release: 10.8.13 - by TheDreadPirate - 2024-02-15, 03:15 AM
    RE: New Server/Web Hotfix Release: 10.8.13 - by gzowner - 2024-03-08, 04:01 AM
    RE: New Server/Web Hotfix Release: 10.8.13 - by TheDreadPirate - 2024-03-08, 04:17 AM

    • View a Printable Version
    • Subscribe to this thread
    Forum Jump:

    Home · Team · Help · Contact
    © Designed by D&D - Powered by MyBB
    L


    Jellyfin

    The Free Software Media System

    Linear Mode
    Threaded Mode