this post was submitted on 06 Jul 2023
23 points (96.0% liked)

Discussions related to Infosec.pub

1218 readers
1 users here now

founded 2 years ago
MODERATORS
23
submitted 2 years ago* (last edited 2 years ago) by henfredemars to c/infosecpub
 

Be careful what posts you click until this is patched.

EDIT: Clarify, this server I expect is also vulnerable, hence the choice of community.

all 6 comments
sorted by: hot top controversial new old
[–] 21trillionsats 4 points 2 years ago (1 children)

Hits a 404 now on the link (sh.itjust.works link above), does anyone have a TLDR?

[–] henfredemars 9 points 2 years ago* (last edited 2 years ago)

Deleting the post might have been damage control because the disclosure was not responsible. Details are in the project GitHub, but basically it's possible to trick Lemmy into serving injected JavaScript by making a post with a crafted URL.

This could allow a user to compromise the accounts of other users if you can get them to click on your post.

[–] br3ad 4 points 2 years ago

Looks like there are other potential vulnerabilities which makes this issue worse. Possibly CSRF? https://github.com/LemmyNet/lemmy/issues/3505

[–] Vashtea@sh.itjust.works 1 points 2 years ago

I use "top day" when this happens to me.(jerboa)