Embed Notice
HTML Code
Corresponding Notice
- Embed this notice
feld (feld@bikeshed.party)'s status on Friday, 02-Feb-2024 22:40:58 JSTfeld @GossiTheDog
> TBA. This advisory will be edited with more details on 2024/02/15, when admins have been given some time to update, as we think any amount of detail would make it very easy to come up with an exploit.
what is this bullshit? We can just dig through the commits.
I'm guessing this change is related because it seems like "redirect confirmation" not being done correctly would allow you to takeover an account and the "I'll add tests later" seems like they're hiding something.
https://github.com/mastodon/mastodon/pull/28902