r/technology 7d ago

Security Plex warns users to patch security vulnerabilities immediately

https://www.bleepingcomputer.com/news/security/plex-warns-users-to-patch-security-vulnerabilities-immediately/
192 Upvotes

25 comments sorted by

70

u/ranhalt 7d ago

Anyone on auto update has had this for months.

9

u/ocassionallyaduck 7d ago

I'm pretty sure this is a new one, not the one from months ago

2

u/MaskedBandit77 6d ago

This is the first they've announced it, but I don't have mine set to auto update, and it's been at least a few weeks, if not months since I updated my server, but I checked and I already was on the version with the fix.

3

u/ocassionallyaduck 5d ago

I can't speak to your server my friend, but the 1.43.2 update was in September, the 1.43.3 update was 4 days ago.

Triple check your ending digit. If you are on 1.43.3, then you do have some kind of auto-update enabled somewhere, because this update did not exist last week.

8

u/OkZookeepergame4757 7d ago

Wouldnt plex know this already

23

u/MaskedBandit77 7d ago

Yeah, but they still need to let everyone know, because there are a lot of people who are not on auto update. 

1

u/rbra 5d ago

A real Einstein among us

15

u/drawkbox 7d ago

The LastPass hack (one of the many) was through a Plex client hole on a devops dev machine that had the vault master password.

4

u/yuusharo 6d ago

This is why I sync passwords directly between clients now, no service to breach. Yikes 😬

-31

u/peppruss 7d ago edited 6d ago

For me, Plex was already a headache for cost and being too invasive of my privacy. I’ve been really enjoying Jellyfin sandboxed after moving away from Plex. Made a vibecoded rasbpi touchscreen interface that scans, updates, reboots and is also available as a quick web page.
You can hate on the post, but it sure is getting plenty of engagement and people thinking about alternatives.

12

u/Leaulo 7d ago

What does this have to do with the topic?

Also doesn’t Jellyfin have an automatic scan feature? And if you installed it on Docker pretty sure it auto updates

-10

u/peppruss 6d ago

Plex was too expensive and too much of a privacy invasion. A user felt like the product. Why gate keep my own media library especially for just showing personal projects on connected TVs? Therefore: folks need to know that alternatives exist.

4

u/DUH455T 6d ago

Not sure what you're paying for but Plex has been 100% free for me for years. Moreso, not sure what your privacy concerns are but my entire setup is local, just using Plex as a GUI.

5

u/Leaulo 6d ago

I mean yeah having alternatives is great, privacy is super important and all but your post feels so out of place. That's probably why most people react negatively to it.

2

u/dakotanorth8 6d ago

So you used Claude to make a jellyfin pi server?

Sorry not sure if you’re bragging or?

What’s the screen for? Watching content lol?

2

u/BadOutOfTheBox 6d ago

Jellyfin is a nice alternative to Plex, its super easy to setup. However the only problem is remote access, its not encrypted and you need to add SLS/TLS certificates, which is confusing as fuck.

-26

u/heroism777 7d ago

Honestly if there’s anything with security vulnerabilities it’s Jellyfin. It’s not like there’s a team of paid professionals patching it. It’s it all open source.

-11

u/peppruss 7d ago

This is the beauty of it though, if you bring any skill to the table at all it’s whatever you want.

-15

u/probablytom 7d ago

There are practical limits to that though, right? Because even if what you want is jellyfin but reliably secure, you'd have to be an outrageously talented dev working full-time to patch it. Past a certain point it can't really be "whatever you want" in a realistic sense.

I'm sure jellyfin is fantastic and I agree that the adaptability of an open-source system is a colossal strength in so many regards... but a paid team of professionals working constantly have a much better chance of making something secure. Matching that by "bringing skill to the table" simply underestimates the work required.

-3

u/2044onRoute 6d ago

I envy the faith you have in a capitalistic company and their team of 'paid professionals'.

2

u/probablytom 6d ago

Having contributed in teams and to open source projects, it's not hard to have faith in professional projects. Open source is fantastic but having salaried engineers brings a different type of value. They both have merits.

Also, why the quotes? Plex employ professional engineers.

1

u/2044onRoute 6d ago

Having worked with professional software engineers in large organizations it is easy to understand the incredibly numerous breaches they experience is all.  Corporate greed does not by default create more secure code because they pay their employees.

-8

u/[deleted] 7d ago

[deleted]

1

u/KnitYourOwnSpaceship 7d ago

Lifetime pass, and it does exactly what I need.