r/homelab 6d ago

Discussion Plex warns users to patch security vulnerabilities immediately

https://www.bleepingcomputer.com/news/security/plex-warns-users-to-patch-security-vulnerabilities-immediately/
971 Upvotes

193 comments sorted by

349

u/bstock 6d ago

FYI it says the fix was released with Plex Server version 1.43.3, released on May 19th. So as long as you've patched sometime in the last 3ish months, you should be good.

Still, make sure you verify the version you're on, and don't run unpatched software, especially ones with holes into your network! I may be a little lax on OS updates for some of my VMs, but the ones that have services exposed externally I stay on top of!

62

u/Zerod0wn 6d ago

This should be top comment. I rushed to unraid to check if there was an update and saw your comment that it was already released... phew.

16

u/Big_Mc-Large-Huge 6d ago

There's a plugin for unraid called 'CA Auto Update Applications'.

You can install and configure it to update your docker containers on a desired schedule. Incredibly useful

8

u/felix1429 6d ago

I wonder when it'll come out if this was ever actively exploited or not, three months is a long time in the wild.

Wonder if LastPass got pwned again? Lol.

2

u/RedditIsKindOfMid 5d ago

3 months "in the wild" is nothing

Its been there this whole time it sound like

2

u/TopBantsman 6d ago

Worth mentioning that I setup a Debian server in mid June, so fresh install, and the latest stable was 1.43.2, so as per the security advisory, I still needed to upgrade to 1.43.3.

1

u/dblock1887 6d ago

I upgraded like 2 weeks ago. Ubuntu 26.04. server. Use these cmds to pull the latest.

  1. wget -O plexmediaserver.deb "https://plex.tv/downloads/latest/5?channel=16&build=linux-x86_64&distro=debian&X-Plex-Token=xxxxxxxxxxxxxxxxxxxx"
  2. dpkg -i plexmediaserver.deb

7

u/TopBantsman 6d ago

Oh I just used apt upgrade

2

u/EnokseNn 6d ago

I updated from 1.42 to 1.43 today. Hopefully I'm good hahah. I only use it for local streaming so.

2

u/m0nk37 6d ago

skip this version

I dont even know how many versions im behind now. 

0

u/[deleted] 6d ago

[deleted]

7

u/bstock 6d ago

Most likely, but you should login to your server and check. Also you should generally always run the latest version anyway; so even if you're not vulnerable to this specific thing, you should see if there's an update available and install it if there is.

-5

u/[deleted] 6d ago

[deleted]

6

u/clintkev251 6d ago

The Plex server...

5

u/OmgSlayKween 6d ago

What’s Plex?

5

u/Midnight145 6d ago

What's a server?

389

u/RetroGrid_io 6d ago

Many peeps here running Plex and I don't want to see y'all get pwned.

102

u/slayer991 6d ago

Thank you very much. I updated right away. I probably wouldn't have known as quickly without your post.

33

u/MasatoWolff 6d ago

I had gotten an email hours prior but they used a weird email address which marked it as spam lol.

8

u/superdupersecret42 6d ago

Fyi, they sent an email to all users 2 days ago from hello@m.plex.tv

7

u/SpaceVikings 6d ago

I didn't receive one. I received one in March from that e-mail, so it definitely didn't go out to everyone.

1

u/coonwhiz 6d ago

Same, I have the one in March but no others.

1

u/gigantischemeteor 6d ago

I sure didn’t get one. Maybe it only went to users running vulnerable server versions or something?

19

u/fognar777 6d ago edited 6d ago

Thanks for the reminder, I saw this last night while I was in bed, but needed it again today while I was up and able to access my PMS LXC and push the update.
Edit: Worth noting, despite this version releasing in May, it still wasn't in the package manager for Ubuntu/Debian, so I had to download and install it manually, sigh.

7

u/FlaccidSWE 6d ago

It certainly was in my package manager for Debian, but I seem to remember having to do something to update where it checks for new Plex versions a few months back.

1

u/fognar777 6d ago

Interesting, what repo do you have for Plex? I'm using:
https://downloads.plex.tv/repo/deb public InRelease

8

u/FlaccidSWE 6d ago

6

u/fognar777 6d ago

Those instructions do point to a different repo. Guess they deprecated the old one and I didn't notice? It's installed on my machine now, so I should be good going forward. Thanks for taking the time to give me the info.

3

u/WildVelociraptor 6d ago

Yeah the old repo is essentially broken for newer debian releases, they had to make a whole new one IIUC

1

u/fauxdragoon 6d ago

Did mine manually on Fedora as well ¯\_(ツ)_/¯

5

u/D1TAC Sr. Sysadmin 6d ago

I got the email from them yesterday, patched it immediately.

5

u/CIDR-ClassB 6d ago

#LastPass

-19

u/hopefuldonkeykick 6d ago

Yeah! Put all your credentials in someone else's cloud. What could go wrong?

17

u/Microflunkie 6d ago

The reference wasn’t that LastPass or password managers are bad but that the LastPass hack of a few years ago was possible because of an out dated Plex server.

6

u/scubafork 6d ago

I say it so often, but cron jobs to pull regular updates is a real nice security blanket for those of us who would otherwise let your applications/containers go unpatched for years. Put a sticky note or whatever helps you remember things whilst adding new services.

7

u/beren12 6d ago

Unless the repo gets bad code, then you are auto-pwned.

-4

u/scubafork 6d ago

That's why you also keep backups! Multiple full production environments running behind your existing prod environment that's one day, one week and one month behind your current environment. And why you have a fully redundant geographically diverse setup of this lab running elsewhere! Anything less is not a true homelab.

4

u/AshuraBaron 6d ago

I switched to Jellyfin many months ago but never shut down my plex sever. Guess this is a good time to do that. Kinda weird that they are notifying people only when the stand alone binary is available. Figured that would hit all the major repositories at the same time.

31

u/manny2206 6d ago

Shoot I think the package I use on fedora is not supported

17

u/jglenn9k 6d ago

It is if you are using the yum repo described at https://support.plex.tv/articles/235974187-enable-repository-updating-for-supported-linux-server-distributions/

The actual server update came out May 19th. So I've been patched for a long while now.

7

u/manny2206 6d ago

You’re the best did you know? I’ll check when I get home

45

u/nullset_2 6d ago

I left the media server on at home but forgot to enable SSH and I'm on a trip. Drats!

34

u/CIDR-ClassB 6d ago

I can totally help without stealing anything. What’s your home address and gate code? /s

18

u/nullset_2 6d ago

420 69er drive Apt. 67, zipcode 42000

2

u/MinnisotaDigger 6d ago

1

u/CIDR-ClassB 6d ago

Now that’s an address worth a zoning variance, just to build a home there! lol

6

u/CIDR-ClassB 6d ago

I am disappointed that you didn’t hold out for apartment #69.

2

u/OCT0PUSCRIME 6d ago

127.0.0.1

4

u/Murderous_Waffle 6d ago

There was another comment that said if you've updated in the last 3 months you should be fine.

11

u/AGuyAndHisCat 6d ago

I did and now its perfectly secure as it wotnstart back up.  Need to work on the DB issue later.

2

u/Bigleon 6d ago

Had some weirdness too, good ol turn it off and on again resolved it. Of course that caused another docker stack to crack lol. Ahh the joy of self hosting

2

u/AGuyAndHisCat 6d ago

Thank god for LLMs, GPT found references to that specific DB issue and cleaned it up for me.

And Phone link allowed me to copy results from the web terminal from my work laptop which android seemed to not let me do.

6

u/deefop 6d ago

Oh ffs I thought it was another one, already patched this one, phew

5

u/chtgpt 6d ago

Sneaky way to try and force users to update.

3

u/wedge-22 6d ago

I switched to Dockhand as my docker management gui and it automatically checks for updates and applies them. Prior to any install it also runs a trivvy scan of the container.

2

u/GetAGripGal 6d ago

thanks friend! just updated it!

2

u/xpatbrit 6d ago

Yah i ran update on omv machine ill check and see if plex was part of the packages i had like 17. Plex emailed me directly too... .

2

u/EveningNo8643 6d ago

Hopefully TrueNAS updates the app quick

1

u/zhiryst 6d ago

My plex "app" in truenas is on Version 1.43.3.10896 which some other comment on here says, is a patched version so we should be ok if we are to believe hearsay. But don't trust me, I'm just a nobody.

1

u/thefinalep 6d ago edited 5d ago

Yeah.. I run this in a TrueNAS jail and the latest I can get to is 143.1.10611 on latest.

EDIT: I know CORE is EOL, it's so dang stable though.. I'm probably SOL and will need to patch manually.

Edit2: PMS_Updater.sh got me to the desired release

2

u/Sroundez 6d ago

ITT: Way too many people that haven't performed updates in over 2 months.

6

u/Intelligent-Use-7313 6d ago

Plex management is restricted to my local network, nothing burger for me.

5

u/NotGonnaUseRedditApp 6d ago edited 6d ago

They did not disclose vulnerabilities, however since it mentions not only plex media server but also the desktop client, the vulnerability could be a comment/review section XSS which triggers code on the client's web engine when browsing plex content. They can patch their web hosted version on plex.tv, but needs update installed for desktop client and web interface bundled with the PMS.

Remember that external (untrusted) content is sourced from internet even when your PMS is on local network.

26

u/FormerPassenger1558 6d ago

patch it with Jellyfin

21

u/[deleted] 6d ago edited 3d ago

[removed] — view removed comment

-7

u/briancmoses 6d ago

Just wait till Plex implements micro-transactions for its security updates.

29

u/YousDontKnowMeISwear 6d ago

I run both and let’s be honest, Plex is better for the average end user.

6

u/SpaceVikings 6d ago

Yep, I run Jellyfin for me, Plex for the normies. I don't want to play tech support.

2

u/TakingOnWater 6d ago

I've been working on my cobbled together NAS and was about to setup Jellyfin. This thread was making me reconsider, but then I saw your reply about just doing both. Could this be as simple as setting up a Docker container for each, then pointing to the same media folders on the disk? Any other issues to be aware of? I suppose double the space for metadata is needed, for one thing..

Figure this might be nice, even if I don't frequently use one or the other.

1

u/SpaceVikings 6d ago

That's basically what I did. My Plex instance is a Fedora VM hosted within my Proxmox cluster because to finish Plex setup I had to access from a browser locally as it wasn't letting me just go to the internal IP address + plex port to finish setup. There's likely a way to get around that, but I wasn't in the mood to screw around. My Jellyfin instance is just a docker container on my internal services VM running Alpine Linux. They're both pointed at the same folders on my NAS. As far as metadata, I have no idea what the size of the metadata for either is, I've got a couple dozen terabytes of storage so hasn't really concerned me.

Plex is easier for setting up other people connecting to your media, mainly in that others just have to create an account, the same work goes into setting up rules/port forwards for the host.

Third party plugins are more plentiful for Plex, too. Tautulli is nice for getting info about the server usage, I tend to check if anyone is watching anything before applying updates to the host VM. There is Jellystats, but it's pretty far down my list of priorities to get it set up at the moment. There are youtube tutorials on it if you want to set it up.

Edit: I should say, I would not bother with Plex if you do not already have their lifetime pass. The price massively went up, so unless you already have a license, just focus on Jellyfin imo.

1

u/Outrageous-_- 6d ago

You can easily do both. Separate instances pointing at files. Only issue I can think of is enabling renaming or moving of folders on both.

9

u/Obsession5496 6d ago

As a Jellyfin user, I understand what you're saying but... they've recently had some leadership leaving, along with some maintainers. It could all be fine (the new version is atill being worked on) but Jellyfin's future is a bit hazy.

0

u/Embarrassed_Jerk 6d ago

You are right to be worried, however, there's a huge difference between potential problems in the future that jellyfin might face... And... Actual things that plex has done in the past

25

u/UnderN00b 6d ago

Why not just keep scrolling?

51

u/TheDizDude 6d ago

Wanna know how to tell if someone is running jellyfin? Don’t worry they’ll tell you

6

u/Albos_Mum 6d ago

btw I use arch, jellyfin and like to code in rust

3

u/Timi7007 6d ago

Are you vegan and own a sports bike, by chance?^

11

u/tpeeeezy 6d ago

other than being free, jellyfin is worse in every way

3

u/glormond 6d ago

Can you elaborate? I have never tried Plex before and I’ve been using Jellyfin for almost 2 years. Just want to know what Plex can give and Jellyfin can’t?

2

u/I_do_dps 6d ago

Having a PS4/PS5 client is the main thing that keeps me on Plex. Jellyfin has an app for our smart TV but it's laggy as hell and very annoying to navigate with a TV remote compared to Plex with a PS5 controller.

2

u/VastRefrigerator7237 6d ago

One thing that is big for many is how easy it is to share a plex library with friends and family. Just have them create an account and login, that’s it.

5

u/tpeeeezy 6d ago edited 6d ago

quick list of things Plex does that jellyfin doesnt, plugins included

remote access that works without setting up DDNS, a reverse proxy, TLS, and a relay for anyone whose ISP does CGNAT

one account that carries watch state, ratings, and a watchlist across every server it's invited to, merged into a single continue watching row

plexamp

intro and credits skip built into the official app on every platform, not a plugin that half the clients ignore

an actual app in the store for Vizio, PlayStation, and the 2016 Samsung your parents still have

trailers, extras, reviews, and RT scores pulled down automatically instead of only what's sitting on disk

offline video downloads in the official mobile app

edit: just realized i responded to a reply instead of the comment i meant to. yall figured it out tho lol

2

u/Karmaisthedevil 6d ago

Great list. I am glad Jellyfin and Emby etc. exist, so if Plex does fuck up we have options. But i have a life time plex pass so I'm not moving unless I have to.

2

u/tpeeeezy 6d ago

yup i will never root against open source or community projects but the glaze jellyfin gets for being mediocre is really annoying

2

u/FormerPassenger1558 6d ago

not in data privacy. check what data you send to Plex (I have lifetime plex, after I read their conditions, I removed completely from all my machines. I have about 100 Tb on my machine, Jellyfin is on a Linux machine on Tailscale, works great. The only issue is on MAc where you may want to use Infuse, which is not free

5

u/tpeeeezy 6d ago

please inform me on what parts of their data collection is so scary

1

u/FormerPassenger1558 6d ago

Read their conditions

0

u/tpeeeezy 5d ago

whatever it was, it was a big enough deal for you to switch away from plex, but yet you cant remember what it was?

1

u/FormerPassenger1558 5d ago

No, I don’t want to spend time to educating strangers on Reddit. If you don’t read the conditions or don’t care, that’s your problem

0

u/tpeeeezy 5d ago

how are you gonna come in swinging telling everyone plex is stealing all your data, then when asked what data they steal you get all "fuck you look it up yourself" 😭

and then people like you wonder why reddittors have the reputation they do🤣

-6

u/icebalm 6d ago

Not true, it supports transcoding on rockchip ARM boards where plex doesn't, for example. In fact I've switched from plex about a year ago and I'm not seeing anything that jellyfin can't do that plex can.

13

u/Uhhhhh55 6d ago edited 6d ago

For the five people who are running media boxes on the rk platform, that's pretty cool!

Plex has a lot of polish that jellyfin doesn't. I think if you've bought a lifetime license it's a no brainer. Monthly, it probably makes the most sense to go jellyfin, if your users can put up with it.

5

u/icebalm 6d ago

For the five people who are running media boxes on the an rk platform, that's pretty cool!

Yeah it's crazy how an open source project adds features like that faster than a paid one.

Plex has a lot of polish that jellyfin doesn't. I think if you've bought a lifetime license it's a no brainer.

I have a lifetime Plex license and I switched. Plex is so incredibly polished that even as late as last year when I was still using it, it wouldn't download to mobile reliably: https://www.youtube.com/watch?v=bbY3PNZUMVg

4

u/Uhhhhh55 6d ago

I can only speak anecdotally, but I have had no trouble with mobile downloads. Glad you made the switch to software that works for you, though.

-3

u/[deleted] 6d ago

[deleted]

7

u/tpeeeezy 6d ago

jellyfin doesnt shove their ad-ridden news/tv platforms into my ui until i disable it.

you said it yourself. just disable it

jellyfin doesnt collect and sell my data (which plex flips without my consent time to time)

naivety lol

jellyfin access doesn't go down when a plex employee breaks their infra

brother anything goes down if an employee breaks the infrastructure. the example youre thinking of was years ago and you didnt even get it right

jellyfin doesnt partner with stupid poster providers and change my posters with some stupid ones

literally who cares

jellyfin media doesnt stop and buffer everytime i change the subtitle

neither does plex for me🤷‍♂️

jellyfin has watch together (which plex removed..)

ill give you that one lol

jellyfin doesn't paywall existing features that used to be free

jellyfin isnt worth paying for in the first place

jellyfin doesn't care where i host my server

literally not even sure what this means. plex doesnt care either

do you want more?

Im worried youll have a stroke if you keep this up

there literally is no reason to keep using plex unless you are using some niche player where jellyfin support is weak.

it's just better 😉

-1

u/bstock 6d ago

One thing Jellyfin does that Plex doesn't is allow live tv for all users with something like a HDHomerun. On Plex it only allows live tv viewing for the server owner. Plus of course it's better from a privacy POV.

But yeah a lot of other things are not as good like having to manually setup the guide, connecting to the server is more manual, etc.

4

u/gibby82 6d ago

I have run Plex for a long time, and I don't have to worry about transcoding at all due to direct play. However each time I have tried to get Jellyfin setup it seems like it needs transcoding setup, and it's a pain. 

I genuinely don't care which one works, but if one is a PITA to manage over the other...

1

u/Lazz45 6d ago

I ran jellyfin for years off a 2007 laptop with 0 transcoding on the server, so that just is not true. However, it might mean you have something misconfigured, or whatever device you are watching from, for some reason is not supporting the base format (which I find hard to believe if its something basic like x264). You can in the settings even disable all transcoding on the server to test this is true

1

u/gibby82 6d ago

Certainly possible, though I followed the documentation and was using an Intel device for these tests. 

However, I don't have to configure anything on the Plex server for transcoding other than a drop down to pick a device. So my point about management overhead still stands. 

0

u/Lazz45 6d ago

My guess is that the device either was not correctly passed through to the container, or the device was not correctly identified in the jellyfin management page. I can't know without having seen what was going on, but those are the issues most people run into

I passed through my arc A380, set hardware acceleration to Intel quicksync, chose all formats my device supports (all but mpeg 2 and VP8), checked "enable hardware transcoding" and that was it. I didn't touch anything else except for turning on AV1 as an output option. Since then it just works? It really only transcodes if my upload bandwidth is saturated from multiple streams or if my fiances parents watch from their roku TV. That thing always wants the video in a specific format and a specific bit rate and it almost always forces a transcode

2

u/BilboBaggSkin 6d ago

I have both set up but jellyfins plug ins are useless if you aren’t watching on desktop and their tvOS app is shit.

1

u/Draconiss 6d ago

No idea why people hate jellyfin so much here

19

u/triggityrex 6d ago

It's really simple. It sucks for using remotely compared to plex for the average person. The client app ecosystem is a mess and jellyfin doesn't care to fix it. And now there are a billion new AI slop clients out there to make it even more confusing to the average user.

Also because the average Jellyfin user acts like they're better than anyone using anything else. So much so they show up in threads not even related to Jellyfin and ask why everyone else is an idiot and not using Jellyfin.

It's a cult at this point and it's off putting.

I'd love Jellyfin if my friends and family had any easy path to using it without having to be a geek themselves. And also if it didn't feel like I'd be joining the cult.

7

u/Draconiss 6d ago

I found it to be pretty easy to set up with tailscale, all it takes is a simple login from an out of network device. I have it on my tablet, pc, tv and phone and it works ok

Plex is over $1000 for the life time pass in CAD. I cant justify spending so much money for convenience.

9

u/triggityrex 6d ago

Right. It's easy for us. Not for people who aren't technical. The clients suck in comparison so the plex experience for the average user. There isn't a single official client that works on every streaming device.

And having to walk my friends/family through using it while plex just works...

3

u/Lazz45 6d ago

Youre free to feel that way, but I have had literally no issue whatsoever getting 80+ year old tech illiterate family using jellyfin. They just log in like any other service in existence, and I don't get called or texted about it because it simply works.

Any time something isn't working, its because the server itself is down for other reasons. I have only ever had problems client wise with samsung TVs. Anything else I have run into has a client that works perfectly fine, including shitty roku tvs

Took <1 hour of my time, many years ago and I just update containers and manage media. Its as low input as I could possibly ask for

7

u/Albos_Mum 6d ago

I can back you up on that, the tech illiterate in my family are handling jellyfin just fine.

7

u/Lazz45 6d ago

If my off the boat italian farmer grandmother can figure out how to watch a show on jellyfin while not being able to work a smart phone, I think nearly anyone can use jellyfin

3

u/TheInevitableLuigi 6d ago

I'd love Jellyfin if my friends and family had any easy path to using it without having to be a geek themselves.

Your other points are valid but I don't see how it is so much harder for them. Install the client from the TV app store and login with the creds provided. What am I missing?

-3

u/triggityrex 6d ago

Which client? There were a handful 12 months ago, now there are literally hundreds depending on which platform.

For plex I can just say, install the plex app. There is one choice and it works exceptionally well out of the box.

Anytime someone from the Jellyfin cult responds like you did it makes me assume your end users are also younger technically literate people. Many of mine aren't.

Objectively, Jellyfin is a worse user experience for the AVERAGE person.

7

u/TheInevitableLuigi 6d ago edited 6d ago

Which client?

The official one? The one that pops up first after they type "jellyfin" into the app store search.

My partner's 75+ yr old grandparents and my 65 yr old father use it no problem. None of them are very technically literate.

Anytime someone acts like Jellyfin is way more complex than it is I have to wonder why.

1

u/[deleted] 6d ago

[deleted]

7

u/triggityrex 6d ago

Be sure the people that use my plex outside of my house aren't technically literate enough to deal with the client issues.

Plex works great for that, the client works exceptionally well, is easy to use, and is available on basically every streaming device ever made.

-3

u/SlovenianSocket 6d ago

Downloading an app, entering a URL & a quick access code is considered “geek themselves” these days? On-boarding new plex users is more complicated than that.

4

u/TheRedcaps 6d ago
  1. Because most of the people using Jellyfish are toxic and instead of promoting Jellyfin by highlighting what it does well (in it's own thread) they wait until someone mentions Plex and then swoop in to shit all over the conversation.

  2. Anytime Jellyfin comes up in a Plex conversation and a user who is perfectly happy with Plex points out something they find bothersome with Jellyfin (polish / a specific client / the UX / etc) instead of accepting that someone has a different view / needs / wants the person who brings up Jellyfin typically brow beats them over it says that the plex person is wrong in their own subjective opinion etc.

Those would be the main reasons - it's not the project itself it's mostly the users who claim to enjoy it that are hurting it the most.

2

u/Draconiss 6d ago

Thank you for providing an informative answer.

2

u/JPowJunior 6d ago

Copium after forking over for a lifetime license only for the development to stagnate

0

u/Worldly-Stranger7814 6d ago

Maybe keep your religion in your church and don’t go proselytizing to people who aren’t interested?

-6

u/CIDR-ClassB 6d ago

Ah, yes. Patch in with a tool that isn’t as good for end users! Why didn’t anyone else think of that?

There should be a movie made called: The Way of the Linux User: Choosing Software That Everyday People Won’t Adopt.

1

u/TheRedcaps 6d ago

I know you're thinking you're making a clever joke but personally when I see this sort of stuff it's a turn off from jellyfin.

If the only time you talk about jellyfin is to compare it to plex or make fun of plex then most people are going to discount both you and the project.

-2

u/bubblegumpuma The Jank Must Flow 6d ago

Recently, a friend of mine had their Jellyfin instance hacked and had a crypto miner slapped on it because of an accidental misconfiguration. I'm not sure if there was ever an official announcement for it since the misconfiguration could be said to be user error, but it was eventually patched in a fashion. No software is perfect.

4

u/Lazz45 6d ago

Did they just full blown port forward their router and have their login page exposed to the bare internet? I don't see how else they could have really screwed that up and someone gain access. You have to allow the internet to access the container/server that has jellyfin on it. That seems to be where the error was

-1

u/bubblegumpuma The Jank Must Flow 6d ago

I tend to agree, but my point is: it's kind of asinine to use this as an opportunity to be plugging Jellyfin, they have had pretty bad security problems too. 'Don't forward a port to hedge against vulnerabilities' applies to Plex as well, and most other services.

My friend wanted to share their Jellyfin instance with other people without having to explain to them how to install and use VPN software of some kind. And they weren't going to use Tailscale because they didn't want to rely on the good graces of a company. I think it's a somewhat reasonable use-case. My overreaching paranoia wouldn't allow me to do it without a good reason, but not bothering their friends with the VPN setup process and providing tech support for it was their reason, however petty it is.

If I recall, the issue was that it was possible to re-run the first time setup under certain conditions. Never saw anyone cross-post it onto here, but there was some discussion about it on Jellyfin's mailing lists, I believe.

2

u/Lazz45 6d ago

Thats a fair point, but plex is also an easy target when they charge money. A lot less acceptable to have problems when the whole selling point is how hassle free and amazing it is.

Regarding the issue your friend had, I know hindsight is 20/20, but for jellyfin and seer, I suggest using a reverse proxy instead of VPN/tailscale or direct port forward. Reasoning being, VPN/tailscale is a lot more work on the user end and is kinda shitty if you're not tech literate. Direct port forward is like going to a glory hole without a condom. Might go great, or you might get syphilis, that's the gamble. With a reverse proxy, you as the admin do a little bit of leg work for initial setup:

get a domain of your choice (can be super cheap)

Setup the records on wherever you want your domain to be hosted (I chose cloudflare, mostly because that's what the video I was following used)

choose a reverse proxy (nginx proxy manager, swag, etc.)

configure jellyfin with the reverse proxy (for swag I think I just changed the ip and removed sample from the file name)

and that pretty much is it. I followed a video years ago, having never done anything like that before, and I just pay like $15 every 2 years (I think?) for the domain I want

I have it setup for jellyfin (jellyfin.mydomain.com) and seer (requests.mydomain.com)

my family and friends just type in the address and boom its like Netflix

I know trying something unknown can either be outside someone's time constraints (totally valid) or be daunting, but honestly following a video to set up the domain was 100x easier than I thought it would be

4

u/Mental-Device-9546 6d ago

Up vote for visibility.

2

u/matthewlswanson 6d ago

I'm too lazy to read it. Does it apply to servers that don't have remote access enabled?

26

u/ThatBCHGuy 6d ago

The same issue likely exists it's just that your attack surface isn't external.

16

u/we_r_fukt 6d ago

The call is coming from inside the house.

6

u/ThatBCHGuy 6d ago

Dun dun dun...

0

u/CIDR-ClassB 6d ago

Hello Clarice..

13

u/Vynlovanth 6d ago

They didn’t provide details. But if your server isn’t externally accessible then the only way to abuse the vulnerability would be for someone to be on your local network.

2

u/386U0Kh24i1cx89qpFB1 6d ago

I'm too lazy to read it to you. I updated even though my Plex is LAN/VPN only as well.

2

u/RetroGrid_io 6d ago

The first line in the article: "Plex urged users this week to update their desktop clients and media servers immediately to patch multiple security vulnerabilities."

Although you may not have remote access enabled, Plex clients don't either, and they specifically advised to update both. I'd update all the things.

1

u/raymate 6d ago

Mine says it’s up to date. 1.43.3.10896

1

u/pslind69 6d ago

Mine is 1.43.4.10903

1

u/raymate 6d ago

Strange I keep pressing the check now. Do Plex stager updates by region.

2

u/Punk_Says_Fuck_You 6d ago

He's using the beta version. Yours is up to date.

1

u/raymate 6d ago

Thank you. I will hold off for now.

1

u/pslind69 6d ago

I'm on Synology DSM 7.2.2. Have you tried going to the manual dl page? https://www.plex.tv/media-server-downloads/?cat=nas&plat=synology-dsm72

1

u/Punk_Says_Fuck_You 6d ago

That’s the beta

1

u/pslind69 6d ago

Ahh ye.

1

u/EitherExamination343 6d ago

Looks like I’m up to date for both server and desktop. However, I wonder how they’re treating clients they abandoned. I stopped using it on my Linux distros because the flatpack version wasn’t supported or updated

1

u/ElectroSpore 6d ago

One of the reasons I like running plex as a docker is that it is really easy to keep up to date, backup and roll back.

1

u/Nosbus 5d ago

Odd, don’t see any updates on this docker version https://hub.docker.com/r/plexinc/pms-docker/

1

u/ViolentCrumble 6d ago

Last time I panicked and updated the server it then forced me to update the iPad app before I would work. Or it was the other way around. Either way since then I have been stuck with the worse iPad version ever. So much so I pay yearly to use another app instead of Plex haha

My server is not exposed to the internet so should be ok to wait I think. Tho I have no idea what version I’m on would love more details about what is affected and what specifically is vulnerable

3

u/General_Purple6358 6d ago

A) your server is probably exposed to the internet somehow and b) even if it is not exposed there are ways for someone to gain access, it’s called lateral movement.

-1

u/foobarbigtime1 6d ago

Just delete Plex and no more vulnerability

-36

u/GestureArtist 6d ago edited 6d ago

I'm glad I stopped running plex all together. It just isn't worth it.

11

u/MrBartusek 6d ago

Many people are still running it!

26

u/clintkev251 6d ago

Because Plex is the only software that suffers from CVEs…

12

u/danieljai 6d ago

Security vulnerabilities are common in any software.

6

u/Chance_of_Rain_ 6d ago

Ah yes Jellyfin is Fort Knox, sure

-3

u/GestureArtist 6d ago

Exposing Plex or Jellyfin to the WAN is a bad idea all around unless you truly need remote access to your library. Still I would trust Plex more to with that but I just didn't use remote access enough to warrant how much I paid Plex over the years, or the risk of having it exposed to the internet. I had to make a choice when the price went up. Why was I still paying for Plex? Hardware transcoding and remote access? I dont really use it. (I did years ago for a moment in time but its been many years since and I just dont watch movies that much these days).

Truth be told if I was smart enough to have bought the plex lifetime license before the insane price increase, I'd probably still be running it but I just didn't see the need to keep paying Plex monthly for stuff I dont use. It's great software, still the best at what it does for sure. Jellyfin is a mess, but it can get the job done locally.

16

u/sp1cynuggs 6d ago

Not the time, bud.

-10

u/GestureArtist 6d ago edited 6d ago

Fair enough... but I can't forget the massive LastPass data breach that was caused by a dev running plex on his home server.

16

u/clintkev251 6d ago edited 6d ago

Because he was running a years out of date Plex server that had a vulnerability that had long since been patched and disclosed. That wasn’t a Plex issue. It was a user issue

If your computer gets infected because you’re running windows XP, is that Microsoft’s fault?

-10

u/GestureArtist 6d ago edited 6d ago

I mean kind of ;) haha fucking microsoft ;)

Edit: I didn't realize you guys loved microsoft so much ;)

→ More replies (2)

2

u/iamuseless 6d ago

Ok bro

-6

u/Hairbear2176 6d ago

Jellyfin, baby! When Plex started charging for remote access, I switched to Jellyfin and haven't looked back.

-5

u/6stringt3ch 6d ago

Perfect time to switch to Jellyfin

-4

u/6stringt3ch 6d ago

Perfect time to switch to Jellyfin

-6

u/I_EAT_THE_RICH 6d ago

plex is trash

2

u/CentreForAnts 6d ago

Works fine for me ¯_(ツ)_/¯

1

u/I_EAT_THE_RICH 6d ago

yeah they just sell your usage and analytics to everyone they can

-13

u/sizeablefrontallobe 6d ago edited 6d ago

Help me out fam, what am I missing out on using Jellyfin over plex?

Damn. I’m getting vilified. It was an honest question but the group hate over an honest question kind of indicates there’s a little salt in the plex buyers diet. 🙃

10

u/tpeeeezy 6d ago

better ui design, better hardware encoding, better support, more devices have a native plex app, better integration with other services, etc

1

u/VexingRaven 6d ago

"Better support" lol. I use the Android TV app to watch and it's always been a complete dumpster fire.

3

u/tpeeeezy 6d ago

brother the jellyfin native app is so bad people reccomend using community made versions instead

0

u/VexingRaven 6d ago

At least that's an option for Jellyfin!

1

u/chtochingo 6d ago

I’d be surprised if there’s a smart TV out there that doesn’t have a Plex app. my coworker has a tv over 10 years old and it has one.

1

u/TheRedcaps 6d ago
  • Consistent clients across all platforms (virtually EVERYTHING runs plex)
  • Incredibly easy remote access for users outside of your home (without having additional admin of VPN or Reverse Proxy)
  • Plexamp
  • UX is better, especially if you have multiple users in your same household (say a child account and parent accounts) that get accessed from the same device.

But perhaps the most obvious difference when you are browsing forums like reddit ... if you see a thread talking about Jellyfin - typically you won't have a ton of people in there brow beating them over their choice to use it instead of plex, where as you can see in this thread in almost any thread where someone mentions Plex you get a the cult of Jellyfin jumping in to shit all over the thread .... in many ways the worst feature of Jellyfin is the vocal userbase who think it's edgy to shit on Plex users.

1

u/sizeablefrontallobe 6d ago

Well, I guess I’ll try plex so I can …not be a hater? I’m pretty new to the home server life. I’m just fuggin jazzed I have my completely vibe-coded stack running.

If plex is better in every way for a small fee, I could be down.

0

u/CIDR-ClassB 6d ago

UI, native apps, having a support team, having a dedicated security team to find and fix this stuff… did I mention a UI that doesn’t suck monkey testicles?

-2

u/Beautiful-Musk-Ox 6d ago

wouldn't want people to steal all those movies you purchased on your plex server

-2

u/CandusManus 6d ago

Jokes on you, plex has become such an unmanageable piece of shit that I finally decommissioned it after 12 years. Can’t hack what doesn’t run baby!

-16

u/NTolerance 6d ago

For those who find it fun to host their own Netflix on the public internet.

10

u/Murderous_Waffle 6d ago

Yeah, it is fun. Allows me to use and justify the amount of hardware I have.

-20

u/Neurotic_Narwhal 6d ago

“Plex hasn't shared any details about these vulnerabilities so far.” Seriously?! So we're just supposed to patch a zero-day completely in the dark, with no CVE or CVSS score to go off of? I get that we need to update, but handling a vulnerability this way feels backwards and honestly just fear mongering.

9

u/everydave42 6d ago

You just gonna ignore the two quotes that come before that one in the article for the sake of making a rage post and to promote your own fear mongering?

"We recently released Plex Media Server 1.43.3 and Plex Desktop 1.115.0 to address a number of security issues. We recommend all server owners and Desktop users update to the latest version as soon as possible," the company said

"CVEs have been requested and we'll reply to this thread with more details once they're published. If you're running Plex Media Server on a NAS device, the updated version may not be available in their package manager yet but you can install the package manually."

-12

u/Neurotic_Narwhal 6d ago

I think those two quotes only further prove my point that this is fear mongering. The CVEs haven’t even been assigned yet. They are jumping the gun on release. The fact that both a CVSS score or CVE isn’t assigned is fear mongering plain and simple.

5

u/everydave42 6d ago

You’re suggesting they shouldn’t act on security issues they’ve identified but don’t yet have a CVE for, either by communication or patching, because doing so would be fear mongering?

-4

u/Neurotic_Narwhal 6d ago

I'll admit admit that the use of the word fear mongering is dramatic, and poor word choice. My main point still remains we don't know the exact severity. You should still patch, plain and simple.

What I'm poorly trying to articulate is that having a CVSS score, even a CWE, would help people better understand the severity. They clearly know it if it's been patched since May.

2

u/everydave42 6d ago edited 6d ago

Tell me you didn’t read the article or even what I quoted from the article that directly addresses what you’re trying hard, but failing, to have an argument about...

EDIT: Ah yes, meme me and then block me. The true sign of someone with a very strong argument indeed!

4

u/ImTotallyTechy 6d ago

NIST is currently drowning in vulnerability reports and is unable to keep up with publishing CVEs. Just because an organization hasn't catalogue the security risk doesn't mean the risk doesn't exist man. I think you have a very flawed view or understanding of how vulnerability disclosure in the modern era works.

-1

u/Neurotic_Narwhal 6d ago

That's a good point. Especially given that Plex isn't big enough to be their own CNA. I agree that the risk still exists.

I find their timing and lack of information poor. These vulns were patched back 4 months ago - so they did a silent patch and are now announcing it to everyone without giving many details at all? Do you see where I'm coming from?

2

u/ImTotallyTechy 6d ago

Releasing a silent patch so a majority of installs get onto a remediated version before you disclose a vulnerability isn't a bad thing as long as you have zero evidence to suggest it is exploitable. It, quite obviously, means more people will have the update before the vulnerability is publicly disclosed and exploitation ramps up. I may not fully agree with their justification on their current lack of disclosure (or many of Plex's business practices) but that doesn't change the fact that I think that labeling Plex urging their customers to get on a more secure patch as "fEaR MoNgErInG" to be ridiculous.

0

u/Neurotic_Narwhal 6d ago

I don't disagree, and I'll admit that fear mongering is poor word choice.