As cited
Copy frozen at (site build).
vulnerabilities
Jellyfin 12.0 security fixes arrive alongside the removal of legacy client logins
Jellyfin released version 12.0 with security fixes addressing path traversal vulnerabilities that could expose files outside designated directories, along with improvements to first-run setup, plugin installation, parental controls, and the web interface. The update also removes legacy client login methods and patches an issue where unauthenticated users could access the setup wizard on misconfigured instances.
Why it matters: Operators running Jellyfin media servers should update immediately to close path traversal and unauthenticated setup access vulnerabilities that could lead to data exposure or account compromise.
- Source published
- First seen by Cybersecurity Tracker