this post was submitted on 10 Jul 2023
60 points (100.0% liked)

sh.itjust.works Main Community

7584 readers
1 users here now

Home of the sh.itjust.works instance.

Matrix

founded 1 year ago
MODERATORS
 

There’s plenty of posts on the topic about Lemmy.world being compromised, followed by the exploit being tracked back to an XSS exploit that I believe works on instances with custom emojis enabled. Many instances have been quick to jump on this such as feddit.uk and Behaw which took itself down temporarily.

Does this affect sh.itjust.works?

If so what are the admins doing about it?

Can we get some sort of admin post about this? Last update from them was some time ago.

Hopefully the admins have 2FA enabled on their accounts.

you are viewing a single comment's thread
view the rest of the comments
[–] TheDude@sh.itjust.works 77 points 1 year ago (3 children)

Hey all,

As others mentioned we did not have custom emojis so we were not affected by this particular attack. I have since upgraded our UI to 0.18.2-rc.1 which mitigates this XSS vulnerability.

[–] CannedTuna@sh.itjust.works 14 points 1 year ago

Hey, thanks Dude for your reply! I’m glad to hear this instance isn’t affected and y’all already pushed a fix. Thanks for all you do.

[–] WheeGeetheCat@sh.itjust.works 6 points 1 year ago

Good to know and a strong argument for not jumping to implement brand-new features (let the others be testers haha)

[–] Artemis@sh.itjust.works 1 points 1 year ago (1 children)

I love that you chose TheDude for your account name as the admin of this instance. It just fits so well

[–] CannedTuna@sh.itjust.works 1 points 1 year ago* (last edited 1 year ago)

The Dude abides.

Edit: TheDude@sh.itjust.works instead of “buy me a coffee”, it should be “buy me a White Russian”