this post was submitted on 10 Jul 2023
39 points (95.3% liked)

Mander

432 readers
3 users here now

founded 2 years ago
MODERATORS
 

You guys may want to avoid it until they can sort it out.

you are viewing a single comment's thread
view the rest of the comments
[–] Sal@mander.xyz 19 points 1 year ago* (last edited 1 year ago) (3 children)

Thank you very much for the heads-up! Without this warning I would've gone into my day without patching this...

I've looked looked into it and it turns out that Mander was indeed vulnerable to the exploit, but I can confirm that the exploit was not used here. I've taken the steps that make us no longer vulnerable to this attack. It is best not to release more specific information here because of the nature of the exploit, but if an admin reads this and doesn't know where to find this information they can send me a private message. It is Lemmy-specific, and affects versions >= 0.18.0

EDIT: The details of the vulnerability have now been more publicly released. You can find the details here: https://mander.xyz/post/1080833

[–] GlennMagusHarvey@mander.xyz 3 points 1 year ago

Thank you for being a responsible and responsive admin!

[–] FlyingSquid@mander.xyz 3 points 1 year ago

Thanks as always for your attentiveness and good work!

[–] CamilleMellom@mander.xyz 1 points 1 year ago

Thanks for being so responsive!