You guys may want to avoid it until they can sort it out.

  • SalamanderMA
    link
    English
    20
    edit-2
    11 months ago

    Thank you very much for the heads-up! Without this warning I would’ve gone into my day without patching this…

    I’ve looked looked into it and it turns out that Mander was indeed vulnerable to the exploit, but I can confirm that the exploit was not used here. I’ve taken the steps that make us no longer vulnerable to this attack. It is best not to release more specific information here because of the nature of the exploit, but if an admin reads this and doesn’t know where to find this information they can send me a private message. It is Lemmy-specific, and affects versions >= 0.18.0

    EDIT: The details of the vulnerability have now been more publicly released. You can find the details here: https://mander.xyz/post/1080833

    • @GlennMagusHarvey
      link
      English
      311 months ago

      Thank you for being a responsible and responsive admin!

    • Flying Squid
      link
      English
      311 months ago

      Thanks as always for your attentiveness and good work!

    • @fossilesqueOP
      link
      English
      611 months ago

      I did not link it on purpose. To save you time, tl;dr sketchy links and racial slurs.

      • @SnailMagnitude
        link
        English
        111 months ago

        seems to have been hacked…I would like a source

        sketchy links with racial slurs are better than nothing

        • Sterile_Technique
          link
          fedilink
          811 months ago

          Logged in about an hour ago; promptly redirected to an image of two old men giving eachother a blowjob.

          Didn’t stick around long enough to grab a link lol - lemmy.world is definitely compromised at the moment.

  • @CamilleMellom
    link
    English
    211 months ago

    It seems that the problem is fixed now but the fix is not yet in upstream (should be soon).