jellyfin / jellyfin-plugin-playbackreporting

Playback Statistics Plugin for Jellyfin
https://jellyfin.org
GNU General Public License v3.0
67 stars 25 forks source link

[Security Issue] Registered routes publicly available #23

Closed GigaFyde closed 3 years ago

GigaFyde commented 4 years ago

As of right now, all routes registed by the plugin don't seem to be secured in any way. This means anyone could access and read the data.

Example route: http://localhost:8096/emby/user_usage_stats/user_activity It's not limited to localhost only.

Would like to see this limited to authorized admin users only.

image

oddstr13 commented 3 years ago

This should be fixed now

GigaFyde commented 3 years ago

Happy to report that it's indeed no longer publicly accessible from the looks of it. Greatly appreciated.