You are reading too much into the issue linked.
In order to actually abuse any of the unsecured endpoints, you need to have knowledge of the domain, the media/user/stream IDs and media paths. You don't get those unless you have a user on the Jellyfin instance and brute forcing them is not practical. If you trust the users you add to your Jellyfin instance, there is not much risk in exposing it to the internet.
Those issues definitely need to be addressed at some point, but it doesn't make Jellyfin exposed on the internet open to anyone.