minus-squareSelfhoster1728@infosec.pubtoSelfhosted@lemmy.world•Sharing JellyfinlinkfedilinkEnglisharrow-up14arrow-down3·edit-28 days agoSee this issue on their github repo: here Basically from what I understand there’s loads of unauthenticated api calls, so someone can very easily exploit that. If they just supported mTLS in their clients it wouldn’t be an issue but oh well :( linkfedilink
minus-squareSelfhoster1728@infosec.pubtoSelfhosted@lemmy.world•GameVault Update: Cloud Saves, Steam & Discord Integration, and Affordable Family & Friends PlanlinkfedilinkEnglisharrow-up9·2 months agoOof was looking to start selfhosting this but it has no client Linux support and has a subscription 😬😬 linkfedilink
See this issue on their github repo: here
Basically from what I understand there’s loads of unauthenticated api calls, so someone can very easily exploit that.
If they just supported mTLS in their clients it wouldn’t be an issue but oh well :(