Hi #hometown admins! To keep us up to date with this morning's Mastodon security patches I have released Hometown v1.1.1+4.0.6:
https://github.com/hometown-fork/hometown/releases/tag/v4.0.6%2Bhometown-1.1.1
(This is a second release in two days, containing further bugfixes released by the Mastodon team.)
I'll have a backport for people running the older Hometown version 1.0.8+3.5.5 later today when I'm not stuck on my phone at an airport. Thank you @jasmin and @misty for your help!!
@darius Some of those CVEs are absolutely vicious. I thought log4j was bad!
@darius got the update running well on niagara.social. Really quite lost on how to actually find the nginx config file that to add those hardening lines to though (using proxyed external object storage). Any ideas #mastoadmin ?
Hello again #hometown admins -- there was a bug in Mastodon's security patch that caused issues in the admin panel when viewing remote accounts. They released a fix about 15 minutes ago and I am working to get a Hometown release with that fix very soon.