GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Embed Notice

HTML Code

Corresponding Notice

  1. Embed this notice
    PC-9801 Enjoyer (pawlicker@bae.st)'s status on Friday, 04-Aug-2023 23:46:50 JSTPC-9801 EnjoyerPC-9801 Enjoyer
    in reply to
    • Alex Gleason
    • Oneesan succubus
    @alex @lain >Pleroma is full of security vulnerabilities because OnlyFans paid people on Upwork to implement a bunch of features nobody wants.

    Also there's nobody auditing it. As jank as Mastodon is, they have processes for dealing with this too and a bug bounty.
    https://arstechnica.com/security/2023/07/mastodon-fixes-critical-tootroot-vulnerability-allowing-node-hijacking/
    https://docs.joinmastodon.org/dev/disclosure/
    In conversationFriday, 04-Aug-2023 23:46:50 JST from bae.stpermalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: cdn.arstechnica.net
      Mastodon fixes critical “TootRoot” vulnerability allowing node hijacking
      Most critical of the bugs allowed attackers to root federated instances.
    2. No result found on File_thumbnail lookup.
      Bug bounties and responsible disclosure
      What to do if you found a serious bug
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.