New Jellyfin Server/Web release: 10.11.10

a month ago by 1hitsong to c/jellyfin

We are pleased to announce the latest stable release of Jellyfin, version 10.11.10! This minor release brings several bugfixes to improve your Jellyfin experience. As always, please ensure you take a full backup before upgrading!

You can find the full changelogs on the GitHub releases for the server repository and the web repository.

Release prepared with <3 by @joshuaboniface, the rest of the Jellyfin team, and contributors like you.

Happy watching!

Mountaineer 12 points a month ago

As always, please ensure you stop your Jellyfin server and take a full backup of your metadata/configs before upgrading!

🚀 Jellyfin Server 10.11.10

🔒 Security

Fix GHSA-f47c-m7gr-q92j, by @Shadowghost
Fix GHSA-jg92-mrxq-vv75, by @Shadowghost
Fix GHSA-wwwm-px48-fpvq, by @Shadowghost

📈 General Changes

Fix stale UserData cache [PR #15048], by @theguymadmax
Fix/user manager collation [PR #16906], by @JPVenson

🚀 Jellyfin Web 10.11.10

🔒 Security

Fix xss in listview [PR #7955], by @thornbill
path: 0 23911826, hotness: undefined, score: 12, children: 0
hperrin 7 points a month ago

Yay, Jellyfin!! :D

path: 0 23911495, hotness: undefined, score: 7, children: 0
Semi_Hemi_Demigod 3 points a month ago

Just in time for my first deployment.

path: 0 23912397, hotness: undefined, score: 3, children: 0
Minnels 2 points a month ago

I just installed and fixed my setup yesterday. Sigh Guess the backup part is irelevant at least.

path: 0 23916322, hotness: undefined, score: 2, children: 0
Lemmchen 1 point a month ago

Should I worry that this is essentially a security update for vulnerabilities that are (intentionally?) not explained?

path: 0 23914872, hotness: undefined, score: 1, children: 3
ShortN0te 6 points a month ago

Why should you? They got fixed?

Often security vulnabilities do not go public the moment the got discovered. There are often wirhheld to only the researcher and the team or only a few ppl of the team the vulnabilitie related to.

This is to give system admins time to update and patch their systems before more details and the research gets released.

Responsible disclosure is one of those procedures.

path: 0 23914872 23915914, hotness: undefined, score: 6, children: 0
Prove_your_argument 3 points a month ago

I would update. In a few months those will be published I’m sure.

It’s disappointing that we’ve come to this because when you deal with pcidss or some other regulation frameworks you need to patch or eliminate vulnerabilities and when patching is not feasible you can generally make tweaks to eliminate the attack. I like to apply the same level of hardening to all of my servers and services anyway.. but without details published I have no idea what the vector is or if the vulnerability even applies in my environment - it’s not uncommon for one to require very specific configuration to either be vulnerable or protected.

Easy enough to smash update in this case but still.

path: 0 23914872 23917543, hotness: undefined, score: 3, children: 1
ShortN0te 1 point a month ago

I would update. In a few months those will be published I’m sure.

I mean the patches themself are there and visible. The only thing that is not there is the explenation on what the vulnabilitie is/was.

path: 0 23914872 23917543 23920678, hotness: undefined, score: 1, children: 0
jellyfin
jellyfin

@lemmy.ml

login for more options
9052
449
307

Current stable release: 10.11.11

Community Standards

Website

Forum

GitHub

Documentation

Feature Requests

Matrix (General Information & Help)

Matrix (Announcements)

Matrix (General Development)

Matrix (Off-Topic) - Come get to know the team and blow off steam!

Matrix Space - List of all the available rooms on Matrix.

Discord - Bridged to our Matrix rooms

go to feed...