[Backport release-26.05] jellyfin: miscellaneous security fixes from 12.0 (#562686)

This commit is contained in:
Ihar Hrachyshka
2026-09-21 12:50:23 +00:00
committed by GitHub
2 changed files with 55 additions and 0 deletions

View File

@@ -0,0 +1,26 @@
From 5f13afa1cecfae398ff7d84ed89fc45b14b71c61 Mon Sep 17 00:00:00 2001
From: Shadowghost <Ghost_of_Stone@web.de>
Date: Thu, 4 Jun 2026 19:00:03 +0200
Subject: [PATCH] Fix playlist visibility
---
MediaBrowser.Controller/Entities/Folder.cs | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/MediaBrowser.Controller/Entities/Folder.cs b/MediaBrowser.Controller/Entities/Folder.cs
--- a/MediaBrowser.Controller/Entities/Folder.cs
+++ b/MediaBrowser.Controller/Entities/Folder.cs
@@ -811,7 +811,10 @@ namespace MediaBrowser.Controller.Entities
private bool RequiresPostFiltering2(InternalItemsQuery query)
{
- if (query.IncludeItemTypes.Length == 1 && query.IncludeItemTypes[0] == BaseItemKind.BoxSet)
+ // BoxSets and Playlists can have per-user visibility (shares/open access) that is stored in the
+ // serialized item data and cannot be evaluated by the database query, so filter them in memory.
+ if (query.IncludeItemTypes.Length > 0
+ && query.IncludeItemTypes.All(t => t == BaseItemKind.BoxSet || t == BaseItemKind.Playlist))
{
Logger.LogDebug("Query requires post-filtering due to BoxSet query");
return true;
--
2.51.0

View File

@@ -1,6 +1,7 @@
{
lib,
fetchFromGitHub,
fetchpatch,
nixosTests,
dotnetCorePackages,
buildDotnetModule,
@@ -23,6 +24,34 @@ buildDotnetModule (finalAttrs: {
hash = "sha256-HCs4ZsutVoVH+bBZANjpPeMyV8e63Yemjg9DSr0R9zg=";
};
patches = [
# Prevent SSRF, local file disclosure and DoS via external references in SVG rendering.
# (No public PR.)
(fetchpatch {
url = "https://github.com/jellyfin/jellyfin/commit/cefa78fc1de2410e5c5c6da5062c98fe98b22d17.patch";
hash = "sha256-TxGo+sLLG+C9omxrwvO6byzw+iRqONVLXrQKwkrY22s=";
})
# Fix MaxLoginAttempts not honored.
# https://github.com/jellyfin/jellyfin/pull/17274
(fetchpatch {
url = "https://github.com/jellyfin/jellyfin/commit/8b826d981bcfec22063d6008e38016f4b77790d0.patch";
hash = "sha256-Nav05TcpjBJABybU0BVyJ0UyxKi+6nDNBQ6tjY0DPT8=";
})
# GHSA-9x85-gx46-6522
# Reject user impersonation when retrieving private playlist items.
# (No public PR.)
(fetchpatch {
url = "https://github.com/jellyfin/jellyfin/commit/911ac3769cdcce50a8f6e0b3c0739d509bd9a23f.patch";
hash = "sha256-MwaTwqhuBc7yWW3cL6htlyDQ9O1wt5iFCOM/oVTi6P0=";
})
# Don't let unauthorized users to list other's private playlists.
# https://github.com/jellyfin/jellyfin/pull/17025
./fix-playlist-visibility.patch
];
propagatedBuildInputs = [ sqlite ];
projectFile = "Jellyfin.Server/Jellyfin.Server.csproj";