Also see this topic which was created a year ago where this was asked and no Plex employee responded but one who said he contacted engineering and he couldn’t do more.
I’m a little confused with versions. the post said to update to version 1.43.3 for server but I have 1.43.4. It also says update plex clients to version 1.115.0 but mine say 4.160.0. So I’m a bit confused as to how versions work on different platforms. I’m running Plex server in a Proxmox LXC and clients through a desktop browser.
Is the team working on getting the update into the https://downloads.plex.tv/repo/deb? I only see 1.42.2 there. Based on the tone of the email I got I went to update immediately rather than wait for my nightly upgrade and was surprised to see it wasn’t available. 36 hours later and it’s still not there.
(Yes, I’m aware I can download the .deb manually but that’s not sustainable if the repository isn’t kept up-to-date – I use automated tooling to keep all my gear updated – so I shut the server off in the meantime until I know where my security updates are really coming from.)
Thanks, I can see now that I missed that email. Your team has probably thought of all this, but just in case:
I hope you’ll keep sending out nags for 1.42.3 to those who haven’t upgraded.
I’d recommend adding a highly visible section to the email about the repo change for those whom your records show make use of your .debs.
I’d also recommend returning a 404 for the outdated repo so folks who missed the March email (like me) will see apt-get update failures, which will lead them to the issue.
That is the example given in an advisory asking everyone to move to 1.43.3, and someone will copy it verbatim. Worth correcting.
2. On the CVEs.
CVEs have been requested and we’ll reply to this thread with more details once they’re published.
Is there a rough timeline? Until identifiers exist there is nothing for vulnerability management tooling to key on, so anyone who does not read this forum has no way of learning they are affected. That is the part that matters for people running this in front of a network.
I’ve been wondering about that Flatpak runtime bit. I noticed it a while ago when looking at permissions for my Flatpak packages in Flatseal. I didn’t know if it was a concern or not.
As for the CVE, this has pushed me to disable remote access on my Plex server. I have a VPN connection to the network, and I’m beginning to think that multiple holes in the network are an unnecessary danger. AI-enabled hacks, and CVE’s are becoming an every day thing in my news feeds.