this post was submitted on 15 Aug 2025
69 points (91.6% liked)

Selfhosted

51009 readers
1513 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 2 years ago
MODERATORS
 

Plex has notified some of its users on Thursday to urgently update their media servers due to a recently patched security vulnerability.

The company has yet to assign a CVE-ID to track the flaw and didn't provide additional details regarding the patch, only saying that it impacts Plex Media Server versions 1.41.7.x to 1.42.0.x.

top 50 comments
sorted by: hot top controversial new old
[–] avidamoeba@lemmy.ca 115 points 2 weeks ago* (last edited 2 weeks ago) (1 children)
[–] pHr34kY@lemmy.world 14 points 2 weeks ago (1 children)

I did this a few months back.

Some things aren't as great, but you get full control and your server idles way better on JellyFin.

[–] rumba@lemmy.zip 11 points 2 weeks ago (1 children)

Yeah, as long as you have a decently supported client the entire platform is very serviceable. I do wish they would get rid of the unprotected endpoints and officially support 2FA on the server and clients.

For all their anti-consumer practices Plex does at least take their security very seriously.

[–] fmstrat@lemmy.nowsci.com 10 points 2 weeks ago* (last edited 2 weeks ago) (4 children)

I posted a while back, tested the biggest open endpoints and they were properly secured, the issues just weren't updated.

Note: Plex didn't have SSL, and refused to implement it, until ~6 weeks after I created a POC token exploit. Here's the GitHub repo I posted as a patch before they got their system in order: https://github.com/Fmstrat/plex-ssl. In other words, don't give them too much credit.

load more comments (4 replies)
[–] madiator2011@px.madiator.com 11 points 2 weeks ago (1 children)

I'm on Jellyfin as they banned Hetzner.

[–] madiator2011@px.madiator.com 27 points 2 weeks ago (2 children)

Should clarify Plex banned using Hetzner :)

[–] cupcakezealot@piefed.blahaj.zone 7 points 2 weeks ago (2 children)

i'm ootl; how was plex able to ban them? isn't hetzner just a vps provider? (not questioning you; just curious)

[–] Darkassassin07@lemmy.ca 22 points 2 weeks ago (2 children)

Plex blocked Hetzner IPs, so servers hosted there can't reach plex.tv to auth users or validate plex pass.

[–] cupcakezealot@piefed.blahaj.zone 9 points 2 weeks ago (1 children)
[–] derpgon@programming.dev 6 points 2 weeks ago

That's what you get for using anything that doesn't work fully offline. Seriously people still defending Plex and not seeing that it will bite them back sooner or later are delusional.

Given that hardware doesn't die, my Jellyfin will probably work until the heat death of the universe.

[–] kogasa@programming.dev 1 points 2 weeks ago (1 children)

I've been using a reverse proxy on a Hetzner VPS pointing at my home plex server for years without issue. Maybe this only applies to people running the actual Plex software on a Hetzner VPS?

[–] Darkassassin07@lemmy.ca 1 points 2 weeks ago* (last edited 2 weeks ago)

Yeah, your home server is still able to reach plex.tv so there's no problem there.

It's people actually hosting there that got screwed over.

[–] madiator2011@px.madiator.com 3 points 2 weeks ago

Basically it's possible by checkin IP of the server.

[–] rumba@lemmy.zip 5 points 2 weeks ago

https://torrentfreak.com/plex-will-block-media-servers-at-prevalent-hosting-company-230915/

There's the story but there's not much tea.

I'm guessing there were just enough complaints and Hetzner refused to take anything down.

Really bizarre to license people self-hosting software and then refuse them from hosting it in certain places over what content they choose to put up.

I wonder if they'll just roll through all the VPS now.

load more comments
view more: next ›