Be careful what posts you click until this is patched.

EDIT: Clarify, this server I expect is also vulnerable, hence the choice of community.

4 points

Hits a 404 now on the link (sh.itjust.works link above), does anyone have a TLDR?

permalink
report
reply
8 points
*

Deleting the post might have been damage control because the disclosure was not responsible. Details are in the project GitHub, but basically it’s possible to trick Lemmy into serving injected JavaScript by making a post with a crafted URL.

This could allow a user to compromise the accounts of other users if you can get them to click on your post.

permalink
report
parent
reply
4 points

Looks like there are other potential vulnerabilities which makes this issue worse. Possibly CSRF? https://github.com/LemmyNet/lemmy/issues/3505

permalink
report
reply
1 point

I use “top day” when this happens to me.(jerboa)

permalink
report
reply
1 point
Deleted by creator
permalink
report
reply
1 point
Deleted by creator
permalink
report
reply

Discussions related to Infosec.pub

!infosecpub@infosec.pub

Create post

Community stats

  • 66

    Monthly active users

  • 77

    Posts

  • 251

    Comments

Community moderators