Comment on Ways to Expose Services Publicly
ampersandrew@lemmy.world 14 hours ago By all means correct me if you know more, but what I tend to see is one or two people here saying that Jellyfin devs don’t recommend exposing it publicly, only to be corrected by looking at the actual documentation. I suspect those cautioning against it are on outdated information and that Jellyfin carries much the same risk as exposing any other service.
I think what the devs are saying is ‘don’t expose Jellyfin to the public in an unsafe manner’. I don’t run Jellyfin, but can confirm what you’ve read here. In that vein, don’t expose anything to the public in an unsafe manner.
frongt@lemmy.zip 9 hours ago
There is no safe manner of exposing jellyfin.
Again, I do not run Jellyfin, but what you’re saying seems contradictory to what the devs are implying: here and here. Since I lack the hands on experience, I will leave the issue with the experts.
frongt@lemmy.zip 6 hours ago
That first page says exposing it to the Internet is “not recommended”. Putting a reverse proxy in front of it does not meaningfully change the security posture. A malicious request to
http://jellyfin.homelab.com/exploitable-pagewill be sent to jellyfin in effectively the same way, whether through a reverse proxy or not. You would need a WAF set up specifically to look for relevant exploit attempts.github.com/jellyfin/jellyfin/issues/5415
Those are some outstanding known vulnerabilities, most of them unfixed. They are not particularly severe, but it shows that thorough security is not a priority for the jellyfin devs.