Comment on Jellyfin over the internet
frezik@lemmy.blahaj.zone 2 days agoSpecifically these issues: github.com/jellyfin/jellyfin/issues/5415
The big one is that video/audio playing endpoints can be used without authentication. However, you have to guess a UUID. If Jellyfin is using UUIDv4 (fully random), then this shouldn’t be an issue; the search space is too big. However, many of the other types of UUIDs could hypothetically be enumerated through brute force. I’m not sure what Jellyfin uses for UUIDs.
MaggiWuerze@feddit.org 1 day ago
They don’t. Ids in Jellyfin are based on the path of the file, so easily guessable with a sufficiently large rainbow table