Egregoros

Signal feed

Timeline

Post

Remote status

Context

3

@sharkey@sharkey.team @woof@fedi.aria.dog what the heck else could it even be that's so serious but DOESN'T enable impersonation? based on the description ("I will update for you if you can't do it when it's fresh"), I would assume it's like, RCE or something. but that enables impersonation (and so many worse things). so I guess this vulnerability is definitely less severe than that

(mostly a rhetorical question. I'm thinking out loud here. don't give us more details until the patch is released lol)

@sodiboo @woof @sharkey i mean last time i heard of a vulnerability that was apparently so bad it came from the akkoma team and it was just somebody being able to scrape an actors outbox and look at public posts without doing the signed fetch dance

wasn't enough to warrant an URGENT security update, hopefully a similar situation isn't happening over here and they're patching like.. an xss problem or something

edited: vulnerability was less severe than what i recalled initially

Replies

0

Fetching replies…