

Plex Users Urged To Update Media Server After Security Flaw Exposed (nerds.xyz) 18
BrianFagioli shares a report from NERDS.xyz: If you run Plex Media Server, it's time to drop everything and update. The company has quietly patched a security issue that affects recent versions of its software, and users are being told to upgrade as soon as possible. According to an email Plex sent to affected customers, versions 1.41.7.x through 1.42.0.x are vulnerable. The newly released build, 1.42.1.10060 or later, contains the fix. Plex says the flaw was found through its bug bounty program, but sadly, it has not publicly shared details about how severe the issue is or whether it could be exploited remotely.
Think I'll stay where I am, thanks. (Score:4, Insightful)
There have been multiple bugs that have cropped up in the 1.41.7.x betas through 1.41.9, and I'm not positive they have all been fixed now. I think I'll continue with 1.41.6.9685 for now, since that would pre-date the venerable versions.
Re: Think I'll stay where I am, thanks. (Score:3)
Re: (Score:2)
Re: Think I'll stay where I am, thanks. (Score:2)
Re: (Score:2)
In fact I would posit that LESS obvious bugs are making it to production with AI, but we're trading them for unnecessary complexity and other crap code issues.
Re: Think I'll stay where I am, thanks. (Score:2)
Re: (Score:2)
I think its a symptom of the Elon Musk development model of "Move quickly and break things". The market simply has no patience - you didn't update your app today? Outdated! You didn't update in a week? Obsolete! If you're not pushing 10 updates daily what are your developers doing?
So basically everyone is forced to update frequently and
quietly patched? (Score:2)
How was it quietly patched, when everyone running an outdated server, received an email?
That is the opposite of quiet.
Re: (Score:2)
https://gifyu.com/image/bNRbh [gifyu.com]
Re: (Score:3)
I think the point is they patched it and released a fixed version prior to the venerability becoming public knowledge, instead of users discovering the issue being exploited and then having to wait for a solution from the vendor.
Re: (Score:2)
Not everyone. I get emails from Plex but never got an email about this
Patched (Score:1)
Patched, life moves on, next?
Re: (Score:2)
Exactly.
And if you are running the linuxserver.io container, all you have to do is stop / start the container and it updates itself.
Gee that took me all of 30 seconds. Oh no!
No, thanks (Score:4, Insightful)
Re: (Score:3)
Good for you - but make sure you don't have ports forwarded to Jellyfin. There are well known exploits for user enumeration, unauthenticated playback etc etc that have been open for years.
Only use Jellyfin from remote via a VPN.
Re: (Score:2)
Have stayed on earlier version (Score:3)
I still don't like that Plex forces you to login to THEIR system before you can access YOUR local server. Total crock of crap!
Anyone know a work around for this that -works-?
Re: (Score:2)
https://www.howtogeek.com/3032... [howtogeek.com]
I used this so I could keep playing my content during an extended internet outage