r/PleX 5h ago

Discussion Update Your Plex

331 Upvotes

151 comments sorted by

115

u/ExtensionMarch6812 5h ago

124

u/mahmahmonkey 5h ago

I find the lack of details …. Concerning.

302

u/chris_decker08 Plex Employee 4h ago

Its bad practice to disclose details that attackers can use without giving users a decent amount of time to update. Details will be disclosed at a later point in time.

5

u/TheUnfortunatePanda 2h ago

what are the affected versions?

-68

u/mahmahmonkey 4h ago

You can disclose severity and ease of exploitation, whether unauthenticated remote access is sufficient to exploit etc... give people some idea of the risk. OS Vendors don't typically hide details of security updates until after people update. What's the CVSS score for example?

55

u/CanadianGunNoob 4h ago

If they are making a special announcement about it, It's severe. They aren't going to give details until everybody is patched to avoid giving attackers any hints about how to accomplish the exploit. This is the correct way of doing things.

-38

u/mahmahmonkey 4h ago

They should at a minimum immediately advise if unauthenticated remote access is possible with this vulnerability.

16

u/avodrok 2h ago

Just fucking update and move on

2

u/catinterpreter 6m ago

Unfortunately Plex's record has made it important to ask questions.

7

u/orion2342 2h ago

To give attackers a hint at what is possible due to the vulnerability? NO.

22

u/_badwithcomputer 4h ago

They did
https://forums.plex.tv/t/important-security-update-for-plex-media-server-v1-43-2-and-earlier/942319

  • Vulnerability Fixed: The patch ensures that TranscoderH264Options and TranscoderH264OptionsOverride preferences can no longer be modified over the network.
  • The Risk: Before this fix, unauthorized users or malicious network traffic could potentially alter advanced transcoder arguments. This type of exploit often risks command injection vulnerabilities via downstream utilities like FFmpeg.

-1

u/trevcharm 2h ago

my plex server is behind a cgnat and on vpn without port forwarding, I only use plex over my local home network.

I assume then I'm not vulnerable to this risk?

because new versions of plex server have been terrible for me, would like to avoid updating if it's not too risky.

2

u/_badwithcomputer 2h ago

Hard to really say without reviewing the CVE and exploit proof of concept but it implies that utilities outside of Plex itself can exploit it.

I'd update to be safe then later roll back if it is problematic (very easy to do on Linux)

-70

u/OpaqueCrystalBall 4h ago

No, it's not bad practice, it is good practice.

-56

u/NovaForceElite 4h ago edited 1h ago

I'm sorry, but that is the exact opposite of best practice when it comes to vulnerabilities.

Edit: Y'all can downvote all ya want. It is standard practice to release details on a vulnerability once the patch is ready. Google it, ask ChatGPT, whatever ya gotta do. That's the way it's been for decades.

5

u/valiantiam 2h ago

Not correct. Software will almost always disclose that there is a security vulnerability they discovered but that they will not disclose until a later date because they may not have any known usage of the exploit or very limited use of it out there. Advertising immediately that a very recent version of their software is vulnerable and "here's how you do it/how it's vulnerable" would be insanely stupid.

This is standard operating procedure.

-4

u/NovaForceElite 2h ago edited 2h ago

That's crazy. Every single security alert I'm subscribed to gives info on the vulnerability in the alert. I guess all of the industry leaders in security are doing it wrong. Once a patch is up. The details are released. Details are only held back if a patch is not available yet. That is standard practice. I know because it's what I do at work every day.

2

u/nullb0i 1h ago

Different perspective - this is for something almost entirely used for entertainment. There won’t be any change controls for installation of this patch that would require more information about the why. Additionally, it’s incredibly unkind to release detailed information about a vulnerability that *could* permit an attacker access into people’s homes(I don’t know and it’s not for me to know, yet). Just sayin’

Also, as someone who was subscribed to bugtraq for over 25 years, I would kindly remind you that there have been numerous instances in that span where details were held close to allow the widest dispersion of the announcement and time to mitigate. Context matters and applies.

1

u/NovaForceElite 1h ago edited 1h ago

I can see your point about context. Yes, not all disclosures include details, but that doesn't make it standard practice. For example if the Plex employee I replied to would have said something like "we're not disclosing details at this time, more to come". I wouldn't have even commented. Them saying it's bad practice to release the details is the part I disagree with.

1

u/nullb0i 55m ago

I just reread what he wrote and it’s like a more terse version of what I wrote in my second paragraph. They might be doing the puffery or they might just be keeping their head above water and took time to make a quick comment in a less than fully formed fashion.

0

u/valiantiam 1h ago

Depends on the company truthfully. But it's an extremely common process for companies to withhold their cvd/vuln details until a grace specified grace period to allow for maximum adoption after warning their users.

Some to just name a few... Anthropic Apple Ubiquiti Ubuntu

Some of course release at least the score or high level impact description. But there are plenty of times I see warnings come across my desk that don't disclose any of that until a future date, and usually for decent reason. Such as the exploit is critical and easy to reproduce so disclosure of even the high level description could out users at risk.

2

u/NovaForceElite 1h ago

Just cause some big companies that are more consumer facing don't announce details(usually out of greed rather than proper protocol) with a patch doesn't make it standard practice to not include the details. Maybe that's the difference here. Maybe with direct to consumer software the disclosure process is different, but I can't remember the last time I went to patch a vulnerability and the alert didn't include the info. Heck all the security alerts label them according to severity with the type of vulnerability and CVE if available yet.

37

u/ExtensionMarch6812 4h ago

Assume it’s related to these “fixes” In 1.43.3.10861…

(Security) Address potential vulnerability in the CompanionProxy. (PM-5763)

(Security) The TranscoderH264Options and TranscoderH264OptionsOverride preferences can no longer be modified over the network. (PM-5766)

15

u/_badwithcomputer 4h ago

Generally speaking zero days are reported to the owners of the product, they have some disclosure period to release a patch (which Plex has done), or if a patch is not possible within the disclosure period they can release a mitigation (a config change, or turn off a feature, or add a firewall rule etc which prevents the exploit). At the end of the disclosure period (after ample time to get the patches out) the zero day is published (generally an explanation and proof of concept to recreate) in which time it is no longer valuable to anyone looking to leverage it to attack servers.

21

u/xylopyrography 4h ago

Standard practice, and becoming even more so. Patch notes are going to probably be pushed months past when you need to update in order to slow down attackers.

It's getting hard for humans to keep up.

-35

u/SeeTigerLearn LifeTime PlexPass 4h ago

It is literally why I stopped applying updates from Plex months (years?) ago. I always read the details ahead of time, but they sneaked their abhorrent abomination of a new interface in and killed streaming music or whatever the crap the did. It was never in the specs for the update. Ever since I absolutely do not trust them to have MY best interest at heart.

22

u/Visible-Lingonberry4 4h ago

Oh so you are many security patches behind? What are you, a senior DevOps engineer at lastpass? No way that goes wrong

21

u/merlinus Carthago Delenda Est 4h ago

I did this last week too in my normal routine maintenance updates. But glad you are posting here.

10

u/yibbida 4h ago

Im on 1.43.4 from the update the other day.

3

u/human-derp 1h ago

same. my auto-updater did it! had me confused about this post

2

u/Viver1 3h ago

I just updated it to the same version. We are ahead!

52

u/Meh-Gyver 5h ago

They late. I did this last week.

12

u/CLOBBERTIME Roku 3h ago

Fuck me I hit the skip button in my client because I was trying to watch a movie when it came up

4

u/StringFood 1h ago

i took your glasses because you didn't update your plex. go ahead and check. you will find them quite gone

3

u/sellera 3h ago

you're on 1.43.3.10896 too? do you know if that's the latest version?

i'm running plex on a rasperry pi and updated it last week, iirc.

2

u/southave 1h ago

that's the version I'm on and I updated last week too

19

u/arewecooked 4h ago

“a number of security issues”

that bit and the overall tone of the email… awesome!!!

-21

u/SpaceCurious9001 3h ago

A few of my credit cards and passwords were exposed last week. Maybe related to this? What I think happened is someone was able to access my laptop with Plex server that is always on. They got into my password manager and pulled data.

Word of warning, update Plex and two factor all your financial accounts.

-12

u/arewecooked 3h ago

I’ve had people attempting to get into multiple accounts and I’m wondering if it’s related to this as well. 😵‍💫

5

u/TheUnfortunatePanda 2h ago

I want them to tell me which versions are affected for the vulnerability. Is it all versions of PMS? They can at least say that clearly.

5

u/human-derp 4h ago

im confused. am I late? did they already release another? im on 1.43.4.10903

1

u/Brandi_yyc 3h ago

This is the same version I have, I think I updated sometime last week?

4

u/Kougeru-Sama 37m ago

Plex updates have a history of making things worse so I'd really prefer they tell me WHY before I risk breaking shit on a perfectly working version. Does this exploit require remote access? Give us SOMETHING. Updates are too risky in the current era

11

u/bulyxxx 5h ago

Already did

3

u/MrKyleOwns 3h ago

I don’t have this option to update

27

u/SamURLJackson 5h ago edited 4h ago

The last two releases have stopped responding to client requests entirely for me. No thanks

Edit: my working version is 1.43.2.10687

I have tried the two releases after this one and neither worked so I downgraded back to 1.43.2.10687 both times with great success. The app and logs didn't show me any indication that anything was wrong, but it didn't respond to any requests. Restarting the service worked but only for a minute or two

18

u/PokemonCrazy 4h ago

How are you running Plex? I use Docker and have never had any issues like this.

-7

u/SamURLJackson 4h ago

I don't use docker for Plex. Just a straight install

These last 2 releases it just stops responding. It is running, but my media shows as unavailable. I have to restart plexmediaserver and it is available again for a couple of mins. Over and over. I've kept it downgraded to a version from like Aug 2 and have had not had this issue since that downgrade

7

u/bananapizzaface 4h ago

Check your logs.

1

u/SamURLJackson 4h ago

I have, it shows nothing. From looking at the app and logs you would think it is running fine, but no one can connect to the media server software, locally or remotely. I am placing all of the blame on the software since downgrading has fixed it. I don't get good responses the very few times I've reported issues to plex so I will sit on my Aug 2 release happily

2

u/chris_decker08 Plex Employee 4h ago

Do you happen to have multiple servers on your network? Or are you behind a cgnat?

1

u/SamURLJackson 3h ago

Not behind cgnat. This is my only plex server. The same host runs other applications, but downgrading the plex software fixing my issue, to me, means it is the software causing the issue

2

u/wiser212 4h ago

If you are running Kometa or anything that uses the same token as Plex, it will advertise as Sync on Plex side. You need to generate a separate token for Kometa and the likes. This was not a problem before but the latest updates have this restriction now.

4

u/SamURLJackson 3h ago

I don't run kometa but I do have some apps that ask for plex tokens so that may be a possible cause, thank you

1

u/nbfs-chili 3h ago

Is this true for tautalli?

1

u/wiser212 3h ago

Don’t think Tautali uses a token.

-2

u/General_Problem7957 4h ago

I had the same problem when 1.43.3 first came out. I went back to the previous version of 1.43.2. Until that issue is fixed. I'm not updating. 

2

u/solidfreshdope 5h ago

What was the issue?

1

u/BlackLodgeBrother 5h ago

Same. It’s been such a headache.

13

u/mehalywally 4h ago

After the disaster of the fire tv app update, I don't know if I ever want to update Plex again.

I know this is the server and not the player app...

8

u/CIDR-ClassB 2h ago edited 2h ago

After the disaster of the LastPass breach because an idiot engineer didn’t update a plex instance, I don’t know if I’ll ever delay updating Plex.

You and I may not have the massive troves of data that LastPass lost, but security patches exist for a reason.

0

u/ReverendDizzle 1h ago

Was that the attack vector? That’s crazy.

-3

u/syntaxterror69 3h ago edited 1h ago

Maybe somebody here could let us know if and when its safe again as I also had to roll back the update on FireTV

EDIT: not sure why im getting downvoted if someone could explain it to me

2

u/jgpkxc 3h ago

Thanks for making me aware.

2

u/IdleSteps 2h ago

Huh, I'm already on 1.43.4.10903

Thanks Binhex!

Oh you know, I guess I'm on the Plex Pass branch or whatever?

2

u/m1e1w1 2h ago

So 1.27.2 still running for use with xbox 360 console playback. All the newer versions dont work right. Lots of errors in navigation and playback

2

u/Blaze1337 1h ago

I just received that email, honestly surprised to see such a thing from them.

2

u/obogobo 1h ago

Annoying their apt repo still has 1.42 as the latest. Had to dpkg -i it manually

3

u/Imnotyoursupervisor 4h ago

It’s not ideal but containers, Linux, watchtower on the nickfedor build.

I’d rather have security patches solved as soon as they come out than complain about UI / UX updates.

4

u/Mycat8meagain 5h ago

Be interested to see the issue. was it an opps on the plex side ?

1

u/Affectionate-You7869 5h ago

Mine says it's on Version 4.160.0

15

u/Poop-from-my-butt 5h ago

That’s the web version. Server version is at server settings > general

Current version is 1.43.3.10896
Windows plex.exe is 1.115.0

1

u/Tregonia 2h ago

ok, so if I'm on version 1.43.3.10896 then I'm good correct? I don't need to do anything.

7

u/RScottyL Synology 1522+ NAS 5h ago

It is referring to the SERVER, not the actual web app!

-2

u/Affectionate-You7869 4h ago

Server is on 143.3 🤷

6

u/Jedi-Master_Kenobi 5h ago

Web UI: Settings → General

1

u/modest-pixel 5h ago

What’s special about this update compared to others? Just based on having a life I think I catch every third or fourth update.

13

u/ExtensionMarch6812 5h ago

In 1.43.3.10861 they noted these two security related fixes which may be related to the issues they note they will provide more details about…

(Security) Address potential vulnerability in the CompanionProxy. (PM-5763)

(Security) The TranscoderH264Options and TranscoderH264OptionsOverride preferences can no longer be modified over the network. (PM-5766)

12

u/coyote_den 5h ago

Ooh that sounds like you could inject shell commands via improperly sanitized arguments to ffmpeg. Not good.

12

u/Tramd 5h ago

They sent out an email about it. They don't regularly do that. Sounds like a vulnerability just patched as they mention the CVE will be coming out.

Usually you want to apply this PDQ when they're contacting you directly about it.

4

u/mglatfelterjr 4h ago

Please don't shoot me, what does VCE and PDQ mean? Thanks.

10

u/Tramd 4h ago

CVE stands for Common Vulnerabilities and Exposures. It's how organizations report security incidents: https://app.opencve.io/cve/?vendor=plex

PDQ is just Pretty Damn Quick :D

3

u/mglatfelterjr 4h ago

Thank you, I appreciate that.

2

u/brkgnews 3h ago

RFN > PDQ

2

u/wenestvedt 4h ago

PDQ is "pretty darn quick[ly]" -- install it as soon as possible!

A CVE is the standardized description & serial number for a given security vulnerability. (It actually stands for "Common Vulnerabilities and Exposures.")

2

u/Kougeru-Sama 36m ago

I'm older than dirt and have never seen anyone use "pdq" 

1

u/mglatfelterjr 4h ago

Thank you

2

u/modest-pixel 5h ago

Well I also didn’t get the email but I think that might be because I have my email spam filters set to the same sensitivity of my dog looking for squirrels in the yard.

2

u/atbths 4h ago

FYI anytime after CVE is mentioned, its good to dive in and get things sorted.

2

u/HoneyBaked 5h ago

How is this update going to hose those who haven't updated their server in a long while (those who didn't update so they could avoid all of the bad updates)?

3

u/i_write_bugz 4h ago

Expect some pain

-5

u/earthcharlie 3h ago

Same. Not doubting there are security updates but can’t help but feel like this is sometimes done to force those who choose not to update. 

1

u/HoneyBaked 2h ago

Just updated mine (I can't remember the last time I updated) and everything looks to be ok.

1

u/[deleted] 5h ago

[deleted]

2

u/KuryakinOne 5h ago

Download from plex.tv and manually update.

-7

u/mikebones 4h ago

Imagine not using a container in 2026

1

u/KuryakinOne 29m ago

Imagine using one when completely unnecessary.

1

u/mikebones 7m ago

It makes things significantly easier to maintain, but go off.

1

u/Krojack76 3h ago

Weird. I'm already running Version 1.43.3.10896 and it seems like the last time I updated was a few weeks ago.

1

u/DRTHRVN 2h ago

Are updates already pushed for docker?

1

u/catinterpreter 27m ago

It's annoying that Plex has cultivated enough distrust that I have to wonder if this is a ploy.

1

u/wyrdone42 20m ago

With the release of Anthropic Mythos, which has been fed all open source code and a large swatch of proprietary code from many vendors, new exploits are being found and patched at a highly increased rate.

It's going to be a long and bumpy ride, but in the end more secure code is the end goal.

2

u/ericsmiles2 16m ago

Typical PLEX.

0

u/coyote_den 5h ago

Tl;dr: this email is going out to people who still haven’t updated their servers. If you updated to 1.43.3 in the last couple of weeks you won’t get it. There is no new update.

16

u/Vanterax 5h ago

I have 1.43.3.10896 and still got the email.

3

u/worafish 4h ago

I have this version, received no email, and when I click Check for Updates I get a green check and Up to date.

What is going on?

0

u/Jaybonaut 3h ago

Yep, same version, no email, no update when you check and the front of their website also states that is the latest version: 1.43.3.10896.

-1

u/coyote_den 4h ago

Same. No email, I pulled an updated image as soon as the server told me there was an update. Some who have updated are getting the email anyway.

Plex being plex. They try hard.

0

u/EvenDog6279 Fedora 44, i5-12450H, Docker, Shield Pro 4h ago

Same. I updated as soon as it was available and also got the notification via email.

1

u/the_woodenpickle 5h ago

Ah, thanks.. I was a little worried, so I checked my server version and it matched. Then I noticed on their site the update was posted Aug 12th, and I had updated a week ago according to my Bash history.

0

u/Broad-Translator-690 4h ago

Plex server on ubuntu server here and the snap got updated to 1.43.3 and still got the email.

1

u/sellera 3h ago

i just got the same e-mail, but i'm on 1.43.3.10896.

sudo apt update shows nothing new.

do i have to add another source manually, like some time ago, when we all got disconnected from our servers?

2

u/CIDR-ClassB 2h ago

You can check the details for your system from this forum post.

2

u/sellera 2h ago

I did, thanks, but i couldn’t find any instructions for my system!

Thank you anyway, have a good one, mate!

1

u/donjamica 2h ago

Updated before they sent a comm to update and now my plex is broke. Crappy.
https://giphy.com/gifs/z7K6aAEIMlCeI

1

u/CIDR-ClassB 2h ago

In what way did it break? (So I know what to look out for)

1

u/donjamica 2h ago edited 1h ago

Just quits. Restart server and it quits. Using a Roku.

1

u/No-Sir2294 39m ago

Fuck that never update plex unless it physically won't work. I like my free remote access thanks 😂

0

u/blacksan00 5h ago

lol - I am on the mercy of Synology for any updates on their Plex App.

7

u/ExtensionMarch6812 5h ago

Do a manual update/install via package center. Download the package for your DSM version from plex and you can install it.

https://www.plex.tv/media-server-downloads/?cat=nas&plat=synology-dsm72

8

u/sal9002 5h ago

Install it manually. I do that for every update. 

1

u/hbk72777 2h ago

Just saw this. I'm getting real tired of their bullsht. They keep raising prices but they don't put a dime into security.

0

u/Useful-Milk8995 1h ago

I just need the TV show to go to the next episode on its own. Like it use to. Simple

-2

u/mikebones 4h ago

Ready to move to something open source

-1

u/CIDR-ClassB 2h ago

Open source is no less vulnerable to security issues than Plex.

In fact, plex likely dedicates far more money and resources to finding and fixing security issues than Jellyfin or Emby.

2

u/catinterpreter 18m ago

Plex has a record of inept development. They aren't the crack team you're imagining.

0

u/mikebones 2h ago

You say that very confidentially when we dont know the status of their repository, code scans, pr process, vulnerability scanning, etc etc. Open source is arguably under more scrutiny and active contributors can work towards a better project. Thats why it's no surprise some of the most wildly adopted applications and software trusted by enterprises far bigger than plex not only rely on open source, but also open source their own projects.

0

u/smurfy213 5h ago

I just got the same email.

0

u/Odd_Implement_7918 1h ago

The title got me excited we had a good UI update lol

-17

u/sephrisloth 5h ago

Did they fix the terrible UI? Sick of it taking like 6 clicks to get to my movie library.

-12

u/spinstartshere 5h ago

Cool.

But what about nEw FeAtUrEs?

-7

u/Bloated_Plaid 200 TB unRaid Box, ARC A380, Zidoo Z9x 8K, Nvidia Shield 4h ago

Fucking AI man.

-21

u/AlwaysInTheHood 4h ago

My Plex has been offline for 18 months… My main drive is dying and I don’t want to risk my backup. The increased price in storage made me put my Plex on hiatus until prices drop.

-6

u/Nervous-Possession31 3h ago edited 3h ago

No one wants that new version it sucks I’m talking about the plex for firestick 

-18

u/silverwingsTK 5h ago

Tbh I’ve had much bigger fish to fry on my NAS this week with a runaway event on a core service - once I’ve verified that my system is largely stable I’ll be sure to look into updating my Plex

-1

u/NoobNoob_ 3h ago

It takes you that long to update plex? I just did it on termux from my phone in about 2 minutes, and half of it was spent on typing passwords ON A MOBILE KEYBOARD.

1

u/silverwingsTK 3h ago

It doesn’t but I had serious system instability of the NAS this week, that the source of is still not 100% ascertained. I won’t be making any updates to any of the extra software until I have a few more days of testing and stability under my belt. Whatever Plex has can almost certainly wait until I’m sure I won’t have I/O trashing of my drives again.