There’s plenty of posts on the topic about Lemmy.world being compromised, followed by the exploit being tracked back to an XSS exploit that I believe works on instances with custom emojis enabled. Many instances have been quick to jump on this such as feddit.uk and Behaw which took itself down temporarily.

Does this affect sh.itjust.works?

If so what are the admins doing about it?

Can we get some sort of admin post about this? Last update from them was some time ago.

Hopefully the admins have 2FA enabled on their accounts.

  • @TheDude
    shield
    MA
    link
    English
    771 year ago

    Hey all,

    As others mentioned we did not have custom emojis so we were not affected by this particular attack. I have since upgraded our UI to 0.18.2-rc.1 which mitigates this XSS vulnerability.

    • @CannedTunaOP
      link
      English
      131 year ago

      Hey, thanks Dude for your reply! I’m glad to hear this instance isn’t affected and y’all already pushed a fix. Thanks for all you do.

    • 🐱TheCat
      link
      English
      61 year ago

      Good to know and a strong argument for not jumping to implement brand-new features (let the others be testers haha)

    • @Artemis
      link
      English
      11 year ago

      I love that you chose TheDude for your account name as the admin of this instance. It just fits so well

      • @CannedTunaOP
        link
        English
        1
        edit-2
        1 year ago

        The Dude abides.

        Edit: [email protected] instead of “buy me a coffee”, it should be “buy me a White Russian”

  • @[email protected]
    link
    fedilink
    English
    21
    edit-2
    1 year ago

    sh.itjust.works doesn’t have custom emojis and so is fairly safe from this specific exploit. Only local users of instances with custom emojis were at risk if they had visited a malicious page on their home instance.

    Lemmy-ui pushed a fix for this vulnerability just 8 minutes ago, so we’ll see if that makes it here.

    • @CannedTunaOP
      link
      English
      41 year ago

      Thanks for the heads up!

  • LachlanUnchained
    link
    fedilink
    English
    8
    edit-2
    1 year ago

    2fa could be bypassed. Didn’t matter.

    All instances were equally vulnerable. But not all were targeted.

    Theres been advice on mitigations to prevent this particular vulnerability. If your instance has implemented them, shouldn’t be a problem.

    A UI fix should be pushed shortly.

  • @Artemis
    link
    English
    11 year ago

    deleted by creator