Collection of potential security issues in Jellyfin This is a non exhaustive list of potential security issues found in Jellyfin. Some of these might cause controversy. Some of these are design fla…

  •  t3rmit3   ( @t3rmit3@beehaw.org ) 
    link
    fedilink
    arrow-up
    5
    ·
    edit-2
    8 months ago

    Your smart TV is (presumably) on your local network, so you should be routing the requests locally (point the client at the local ip, assuming it didn’t autodiscover it) not through the VPN/ tunnel.

      •  t3rmit3   ( @t3rmit3@beehaw.org ) 
        link
        fedilink
        arrow-up
        1
        ·
        edit-2
        8 months ago

        In which case there are still ways to make it work, like putting in an SSO bypass rule for the IP of your other property. Point is, under no circumstances is it impossible to both have it be protected against scanning attacks like the ones described in the gh issue, and keep it available to use over the internet for authorized users.