programming.dev
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
ruffsl to Fediverse@lemmy.worldEnglish · 2 years ago

TootRoot | Mastodon had a Critical Security Vulnerability

youtube.com

external-link
message-square
3
link
fedilink
  • cross-posted to:
  • programming
  • security
52
external-link

TootRoot | Mastodon had a Critical Security Vulnerability

youtube.com

ruffsl to Fediverse@lemmy.worldEnglish · 2 years ago
message-square
3
link
fedilink
  • cross-posted to:
  • programming
  • security
Mastodon had a Critical Security Vulnerability
youtube.com
external-link
In this video I discuss the recent security updates to Mastodon to fix critical security vulnerabilities that allowed for cross site scripting through oEmbed...

cross-posted from: https://programming.dev/post/551085

Security advisorys: https://github.com/mastodon/mastodon/security

alert-triangle
You must log in or register to comment.
  • PipedLinkBot@feddit.rocksBannedB
    link
    fedilink
    English
    arrow-up
    21
    ·
    2 years ago

    Here is an alternative Piped link(s): https://piped.video/watch?v=3KCyhltnz7w

    Piped is a privacy-respecting open-source alternative frontend to YouTube.

    I’m open-source, check me out at GitHub.

  • ruffslOP
    link
    fedilink
    English
    arrow-up
    10
    ·
    2 years ago

    For anybody wondering what the Mastodon security issue is - CVE-2023-36460, you can send a toot which makes a webshell on instances that process said toot. #CVE202336460 #TootRoot

    • https://cyberplace.social/@GossiTheDog/110667416012211236
  • samokosik@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    ·
    2 years ago

    hopefully more detailed analysis will come

Fediverse@lemmy.world

fediverse@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

A community to talk about the Fediverse and all it’s related services using ActivityPub (Mastodon, Lemmy, KBin, etc).

If you wanted to get help with moderating your own community then head over to [email protected]!

Rules

  • Posts must be on topic.
  • Be respectful of others.
  • Cite the sources used for graphs and other statistics.
  • Follow the general Lemmy.world rules.

Learn more at these websites: Join The Fediverse Wiki, Fediverse.info, Wikipedia Page, The Federation Info (Stats), FediDB (Stats), Sub Rehab (Reddit Migration)

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 205 users / day
  • 2.44K users / week
  • 6.06K users / month
  • 18.5K users / 6 months
  • 446 local subscribers
  • 33.4K subscribers
  • 2.42K Posts
  • 80.2K Comments
  • Modlog
  • mods:
  • Ruud@lemmy.world
  • Xilly@lemmy.world
  • MrCenny@lemmy.world
  • TragicNotCute@lemmy.world
  • AutoMod - Beta@lemmy.world
  • woelkchen@lemmy.world
  • BE: 0.19.11
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org