K-Money's Lemmy
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
ruffsl@programming.dev to Fediverse@lemmy.worldEnglish · 2 years ago

TootRoot | Mastodon had a Critical Security Vulnerability

youtube.com

external-link
message-square
3
link
fedilink
8
external-link

TootRoot | Mastodon had a Critical Security Vulnerability

youtube.com

ruffsl@programming.dev to Fediverse@lemmy.worldEnglish · 2 years ago
message-square
3
link
fedilink
Mastodon had a Critical Security Vulnerability
youtube.com
external-link
In this video I discuss the recent security updates to Mastodon to fix critical security vulnerabilities that allowed for cross site scripting through oEmbed...

cross-posted from: https://programming.dev/post/551085

Security advisorys: https://github.com/mastodon/mastodon/security

alert-triangle
You must log in or register to comment.
  • samokosik@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    ·
    2 years ago

    hopefully more detailed analysis will come

  • ruffsl@programming.devOP
    link
    fedilink
    English
    arrow-up
    2
    ·
    2 years ago

    For anybody wondering what the Mastodon security issue is - CVE-2023-36460, you can send a toot which makes a webshell on instances that process said toot. #CVE202336460 #TootRoot

    • https://cyberplace.social/@GossiTheDog/110667416012211236
  • PipedLinkBot@feddit.rocksB
    link
    fedilink
    English
    arrow-up
    2
    ·
    2 years ago

    Here is an alternative Piped link(s): https://piped.video/watch?v=3KCyhltnz7w

    Piped is a privacy-respecting open-source alternative frontend to YouTube.

    I’m open-source, check me out at GitHub.

Fediverse@lemmy.world

fediverse@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !fediverse@lemmy.world

A community to talk about the Fediverse and all it’s related services using ActivityPub (Mastodon, Lemmy, KBin, etc).

If you wanted to get help with moderating your own community then head over to !moderators@lemmy.world!

Rules

  • Posts must be on topic.
  • Be respectful of others.
  • Cite the sources used for graphs and other statistics.
  • Follow the general Lemmy.world rules.

Learn more at these websites: Join The Fediverse Wiki, Fediverse.info, Wikipedia Page, The Federation Info (Stats), FediDB (Stats), Sub Rehab (Reddit Migration)

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 118 users / day
  • 2.13K users / week
  • 5.11K users / month
  • 19.4K users / 6 months
  • 1 local subscriber
  • 33.6K subscribers
  • 2.38K Posts
  • 77.6K Comments
  • Modlog
  • mods:
  • Ruud@lemmy.world
  • Xilly@lemmy.world
  • MrCenny@lemmy.world
  • TragicNotCute@lemmy.world
  • AutoMod - Beta@lemmy.world
  • woelkchen@lemmy.world
  • BE: 0.19.11
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org