49
submitted 1 year ago* (last edited 1 year ago) by poVoq@slrpnk.net to c/meta@slrpnk.net

As you might have heard several Lemmy instances have been attacked via a security vulnerability in the browser frontend related to custom emoji.

While SLRPNK was vulnerable to it, we seem to have not been actively targeted and I took the instance down as a precaution as soon as I learned about it.

I have applied all the currently known mitigations, which means that everyone got logged out of their account and needs to log back in manually.

As of writing this the API is working again and can be used with apps like Jerboa safely.

I am still contemplating if I want to re-enable the web frontend now or wait for a release that fixes the issues found.

Edit: the main issue was fixed and I restarted the web ui with it.

you are viewing a single comment's thread
view the rest of the comments
[-] poVoq@slrpnk.net 1 points 1 year ago

You will need to ask this on a kbin community ๐Ÿ˜œ

This is the instance specific one for the slrpnk.net Lemmy instance.

[-] h3x@kbin.social 1 points 1 year ago

For some reason kbin ui shows this thread belongs to kbin.social. Strange!

Anyway, thanks for the correction! :)

this post was submitted on 10 Jul 2023
49 points (98.0% liked)

Meta (slrpnk.net)

505 readers
15 users here now

Here we can discuss anything about this Lemmy instance/server itself.

Our XMPP support chat: Movim or XMPP client.

Please also refer to our Wiki

founded 2 years ago
MODERATORS