Jump to content
quatre1love

Web security bug

Recommended Posts

quatre1love

Hi devs,

The web emby has bug that will expose ther server details to the public even the server has used Cloudflare to protect the IP address.

Input: http://domain/emby/system/info/public, ex: http://demo.emby.tv/emby/system/info/public in the browser, it will show the server details with public IP address.

Please fix this bug ASAP for the security reason.

 

KIND REGARDS

  • Like 1

Share this post


Link to post
Share on other sites
neik

Only thing I see is:

- Server name
- Version
- ID

Which version are you on? I am on the latest beta.

  • Like 1

Share this post


Link to post
Share on other sites
CBers
27 minutes ago, neik said:

Only thing I see is:

- Server name
- Version
- ID

Which version are you on? I am on the latest beta.

@quatre1love must be running Stable, as that does give back the IP address, when it doesn't in Beta. 

You would need to know the server URL in the first place to get that information. 

@Luke

Edited by CBers

Share this post


Link to post
Share on other sites
Q-Droid

This is a known issue that is being worked on and why the beta does not return those details anymore.

 

  • Like 1

Share this post


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×
×
  • Create New...