@thisismissem @pixelfed Consider reporting it to @certbund & @cert_eu ...
Maybe once it's acknowledged then hosters will intervene because they don't want shit to get abused for malware...
Top-level
@thisismissem @pixelfed Consider reporting it to @certbund & @cert_eu ... Maybe once it's acknowledged then hosters will intervene because they don't want shit to get abused for malware... 5 comments
@kkarhan please just wait for the full disclosure on the 25th; I know you're trying to be helpful but you're misunderstanding the type of vulnerability. @thisismissem okay... I do accept amd understand #ResponsibleDisclosure and why people should first fix it... Needless to say said CERTs should be made aware as their publications & feeds are also being read by Hosters who may also have the ability to scan their customers' systems and notify them as well or if necessary forcibly shut down vulnerable instances before they get hacked... @kkarhan there's already a CVE and a security advisory on github. For now it's not necessary as far as I know for CERT to be involved |
@kkarhan @pixelfed @certbund @cert_eu this vulnerability just gives administrative access over the pixelfed software, not to the underlying hardware.