GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Embed Notice

HTML Code

Corresponding Notice

  1. Embed this notice
    Cadu Silva :verifiedcat: (cadusilva@bolha.one)'s status on Wednesday, 26-Mar-2025 07:33:35 JSTCadu Silva :verifiedcat:Cadu Silva :verifiedcat:

    @fediadminbr e demais interessados, vocês viram a última do Pixelfed?

    Depois da história do cache-zumbi (você apaga um post com imagem na sua instância, mas a foto segue viva no cache do Pixelfed alheio), essa é a nova:

    Você tem um perfil trancado e posta só para seguidores. Alguém no Pixelfed seguiu você e foi aprovado. Agora todos os usuários naquela instância Pixelfed podem ler seus posts somente-seguidores.

    :pixelfed: https://chaos.social/@scy/114225428160011112

    In conversationabout 3 months ago from bolha.onepermalink

    Attachments

    1. No result found on File_thumbnail lookup.
      scy (@scy@chaos.social)
      from scy
      Oh, great. #Pixelfed had a broken implementation of "follower-only" posts, _and_ fucked up the disclosure / bugfix release process. https://fokus.cool/2025/03/25/pixelfed-vulnerability.html Summary of the bug: If you have a protected account (on Pixelfed, Mastodon, GTS, whatever) and a Pixelfed user followed you and got approved by you, _all_ users on that instance were now able to see your followers-only posts, not just the one you approved. #Fediverse #ActivityPub #security #fail
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.