Jump to content

Security hole with collections


Recommended Posts

Starlionblue
Posted (edited)

I have some movies in multiple languages for my kids. Swedish Kids Movies and English Kids Movies are in different media folders.

 

I currently have MB set so the kids user only has access to the Swedish Kids Movies media folder (want them to improve their Swedish this summer). The user does not have access to the Collections media folder. Here's where it gets a bit weird. 

 

I have Madagascar 2 in Swedish and English. If I play Madagascar 2, all is fine and I get the Swedish one as expected.

 

However Madagascar 2 is part of the Madagascar collection, which shows up in MediaBrowser. I can see and play the other movies in the collection, even if they are in a media folder that the user does not have access to. Again, the user does not have access to the Collections media folder.

 

Testing on different platforms:

  • MBT. Bug exists. Collections show up and movies in "forbidden" media folders can be played.
  • MB for iPad. Bug exists. Collections show up and movies in "forbidden" media folders can be played.
  • MBC. Things work as they should. Collections do not show up.
  • MB Mobile for iPhone. Things work as they should. Collections do not show up.
  • MB Mobile for Windows Modern. Things work as they should. Collections do not show up.
Edited by Starlionblue
Starlionblue
Posted

Anyone else have this? IMHO it is a rather serious user security hole.

Starlionblue
Posted

Cheers. Let me know if you need logs or anything.

Posted

Yes, I have noticed this as well

Posted

Yes, thank you for reporting it.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...