@PlexTV staff: About the recent security update

You mentioned here that all Plex clients have gotten an update.

https://forums.plex.tv/t/plex-for-mac-windows-and-linux/446435/140

Even the officially supported Snap got this update.

https://snapcraft.io/plex-desktop

But the officially supported Flatpak hasn’t gotten an update in 9 months on version 1.112.0 and is using EOL run time.
https://flathub.org/en/apps/tv.plex.PlexDesktop

Can you please update the officially support Flatpak to that version as well and also update the runtime to a support one when.

There have been PR’s for it been no one has taken any action on this.

https://github.com/flathub/tv.plex.PlexDesktop/pulls

Also see this topic which was created a year ago where this was asked and no Plex employee responded but one who said he contacted engineering and he couldn’t do more.

https://forums.plex.tv/t/plex-tv-plex-plexdesktop-version-1-110-0-flatpak-needs-updating

I’m pretty sure the security update was for the server not client apps.

They explicitly say to update server and desktop, it says so in the first line of the announcement!

I have been told, that Plex is working on this @Cphusion

Sorry, my mistake.

That’s great to hear! Thanks! :slight_smile:

I’m a little confused with versions. the post said to update to version 1.43.3 for server but I have 1.43.4. It also says update plex clients to version 1.115.0 but mine say 4.160.0. So I’m a bit confused as to how versions work on different platforms. I’m running Plex server in a Proxmox LXC and clients through a desktop browser.

Plex Desktop is a desktop client application… It isn’t the same thing as the web client you’re using in browser

Presumably, you’re enrolled in the beta program for the server, as 1.43.4 is listed as available there

Would be nice if they publicized that officially…

We’re working on it.

Is the team working on getting the update into the https://downloads.plex.tv/repo/deb? I only see 1.42.2 there. Based on the tone of the email I got I went to update immediately rather than wait for my nightly upgrade and was surprised to see it wasn’t available. 36 hours later and it’s still not there.

(Yes, I’m aware I can download the .deb manually but that’s not sustainable if the repository isn’t kept up-to-date – I use automated tooling to keep all my gear updated – so I shut the server off in the meantime until I know where my security updates are really coming from.)

Please see: https://support.plex.tv/articles/235974187-enable-repository-updating-for-supported-linux-server-distributions/

Thanks, I can see now that I missed that email. Your team has probably thought of all this, but just in case:

I hope you’ll keep sending out nags for 1.42.3 to those who haven’t upgraded.

I’d recommend adding a highly visible section to the email about the repo change for those whom your records show make use of your .debs.

I’d also recommend returning a 404 for the outdated repo so folks who missed the March email (like me) will see apt-get update failures, which will lead them to the issue.

Thanks again for the help!

Posting here since the announcement thread is closed for replies.

Two things on Important Security Update for Plex Media Server v1.43.2 and earlier.

1. The Linux instructions still reference a 2020 build.

sudo dpkg -i plexmediaserver_1.19.4.2935-79e214ead_amd64.deb

That is the example given in an advisory asking everyone to move to 1.43.3, and someone will copy it verbatim. Worth correcting.

2. On the CVEs.

CVEs have been requested and we’ll reply to this thread with more details once they’re published.

Is there a rough timeline? Until identifiers exist there is nothing for vulnerability management tooling to key on, so anyone who does not read this forum has no way of learning they are affected. That is the part that matters for people running this in front of a network.

Any updates on the desktop flatpak? I just checked Flathub and it’s still 1.112.0. Should I try the snap again if this is truly a critical CVE?

An updates on this, it’s almost been a week?

Nothing yet, sorry

I’ve been wondering about that Flatpak runtime bit. I noticed it a while ago when looking at permissions for my Flatpak packages in Flatseal. I didn’t know if it was a concern or not.

As for the CVE, this has pushed me to disable remote access on my Plex server. I have a VPN connection to the network, and I’m beginning to think that multiple holes in the network are an unnecessary danger. AI-enabled hacks, and CVE’s are becoming an every day thing in my news feeds.

Seems the Flatpak has been updated, finally!

Thanks @PlexTV staff