Critical Vulnerability Exploits Several Lemmy Instances
Critical Vulnerability Exploits Several Lemmy Instances
Several major Lemmy instances were hacked due to an XSS vulnerability. There's a path forward for mitigation, but here's what happened.
Admins, make sure you update to 18.2, this has already been patched:
https://join-lemmy.org/news/2023-07-11_-_Lemmy_Release_v0.18.2
49 0 ReplyDone!
10 0 ReplyBedankt!
5 0 Reply
Luckily it was resolved quickly.
16 0 Replyredirecting users to Lemon Party
I guess it's true; the Fediverse is bringing people back to an earlier time of the internet!
10 0 Replynature is healing!
7 0 Reply
Lemmy.world not really doing much here to convince Beehaw to refederate…
3 0 ReplyNot sure why Lemmy.world is to blame for this - we had the same vulnerability - everyone did. I shut down Beehaw because we had the vulnerability.
62 0 ReplyOh, I know, but this vulnerability + their open signups…
1 0 Reply
It's like Lemmy s01e01 and we already have federation war?
9 0 ReplyIt’s not much of a war. Beehaw is just waiting for better mod tools before refederating.
20 0 ReplyBeehaw.org was at war with Lemmy.world. Beehaw.org had always been at war with Lemmy.world.
9 0 Reply