Untitled attachment
https://files.mastodon.social/media_attachments/files/111/857/027/768/357/938/original/e6834641fc551f2d.png
Thank you @arcanicanis for making us users on here safer and reporting this critical Mastodon vulnerability.
And @Gargron and team for the prompt fix and patching of mastodon.social.
If your instance isn't patched, you should probably ping your admin.
"Due to insufficient origin validation in all Mastodon, attackers can impersonate and take over any remote account.”
https://github.com/mastodon/mastodon/security/advisories/GHSA-3fjr-858r-92rw
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.