Latest Plex Media Server vulnerability #
Plex released a security update for a currently undisclosed vulnerability in certain versions of Plex Media Server. The flaw was reported to Plex through their bug bounty program.
The following versions are affected
- Plex Media Server versions 1.41.7.x through 1.42.0.x
What is the impact? #
The impact of the vulnerability is currently unknown. However, Plex "strongly recommends" that users update to the latest version as quickly as possible.
Are updates or workarounds available? #
Users are encouraged to update to the latest version as quickly as possible:
- Plex Media Server upgrade to version 1.42.1 or later
How to find potentially vulnerable systems with runZero #
From the Software Inventory, use the following query to locate potentially impacted assets:
vendor:=Plex AND product:="Media Server"