Security issue: Media is accesable without login remotely

Steps to replicate:

  1. change your password by selecting “Sign out connected devices after password change”
  2. your are no more logged in but you can access your library/Media without login.

same thing is happening when you remove authorized devices they are able to play your media without login Ex Samsung TV App

Perhaps:

Settings\Network\List of IP addresses and networks that are allowed without auth

Funnily enough I saw this earlier, I logged the server out of my account and all clients on the network could see all libraries regardless of whether they entered the password.

I definitely don’t have the “allow without auth” option selected, I was very surprised to see this on the client.

If you take the server out of your plex account, all clients on the local network can access it without authentication. This is very normal and intended.

This server is not in local network, as mentioned earlier accessing media remotely,
i think some security issue is their which is allowing clients to access media without authorization, check backed logs for this post hopefully you will be able to identify root cause.another security issue

Do you have a Proxy in front of it?
And what version and platform?

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.