https://bsky.app/profile/nih-llamas.bsky.social/post/3komzcim76p26

  • PorkrollPosadist [he/him, they/them]M
    ·
    edit-2
    8 months ago

    There have been several VERY NASTY CVEs since I set up matapacos in 2022.

    Remote code execution: https://github.com/mastodon/mastodon/security/advisories/GHSA-9928-3cp5-93fm A.K.A. "Toot Root"

    Hijacking user accounts: https://github.com/mastodon/mastodon/security/advisories/GHSA-3fjr-858r-92rw

    Among others (there was at least one more really bad one)