78
submitted 2 months ago* (last edited 2 months ago) by taaz@biglemmowski.win to c/lemmy@lemmy.ml

If you are using https://github.com/wereii/lemmy-thumbnail-cleaner please stop and disable it as soon as possible.

We have found a security issue that allows any user to make LTC delete any locally hosted image.

I will be posting more details soon and editing this to include the information.

E: More information here https://github.com/wereii/lemmy-thumbnail-cleaner/issues/10

you are viewing a single comment's thread
view the rest of the comments
[-] taaz@biglemmowski.win 12 points 2 months ago

On point summary.
And I was just about to write that I have confirmed SQLi is not possible to find out I have missed something that might in-turn make it possible! holy hell back to drawing board

[-] Emotet@slrpnk.net 6 points 2 months ago

Yikes. Thanks for putting in the works and sharing your findings to you and @Nothing4You@programming.dev.

this post was submitted on 17 Jul 2024
78 points (100.0% liked)

Lemmy

11947 readers
82 users here now

Everything about Lemmy; bugs, gripes, praises, and advocacy.

For discussion about the lemmy.ml instance, go to !meta@lemmy.ml.

founded 4 years ago
MODERATORS