Embed Notice
HTML Code
Corresponding Notice
- Embed this notice
PC-9801 Enjoyer (pawlicker@bae.st)'s status on Friday, 04-Aug-2023 23:46:50 JSTPC-9801 Enjoyer @alex @lain >Pleroma is full of security vulnerabilities because OnlyFans paid people on Upwork to implement a bunch of features nobody wants.
Also there's nobody auditing it. As jank as Mastodon is, they have processes for dealing with this too and a bug bounty.
https://arstechnica.com/security/2023/07/mastodon-fixes-critical-tootroot-vulnerability-allowing-node-hijacking/
https://docs.joinmastodon.org/dev/disclosure/