82
Hello All,
Due to the incredibly irresponsible disclosure of a security vulnerability for Piefed, we've had to take Piefed.zip offline until a fix can be put in place.
I'll update more once I have more information.
Many thanks
Demigodrick
Thanks for the heads up.
A few months ago I mentioned in a thread about Piefed there were questionable system design choices that indicated that other parts of the system should be carefully examined for how they’re handling and sanitizing input. I'm assuming someone discovered one of the places that this was actively exploitable.
From what I've seen of the code, although Python is not my specialty, it might be worth delaying reactivation until it can demonstrate that it is at least somewhat resistant to the OWASP Top 10, especially Injection.
Irresponsible disclosure is annoying, but vastly better than discovery and exploitation by those who aren't going to disclose at all.
Thank you for taking proactive measures. I hope it gets resolved soon.
Are there any information around the nature of the vulnerability or the status of a fix?
According to this comment https://piefed.social/comment/11352527 fix is expected to take a day.
It was like 40 minutes in the end.
Appreciate the email on this. I don't think I got an email from Piefed.social either. Heck I don't remember getting any from Lemmy.ca for Lemmy downtime. But perhaps they haven't ran into a similar situation.
Thanks, as always, Demigodrick. I'll use my lemmy.zip alt until things are sorted.
GOAT
Most admins would stick their head in the sand. Thank you!
EDIT: This has been resolved thanks to the helpful people on the matrix channel. For anyone else having problems, I just exported my lemmy profile, prettified both json files and manually moved over my blocks and subs then re-imported the modified lemmy file.
Hi there @Demigodrick@lemmy.zip , is there any way to use the piefed.zip export to import to lemmy.zip? I tried since it was mentioned in the email but it just states that the import failed when I try.
Just wondering if I can modify or remove some elements of the file so I can use it to get the blocks and subs imported from my piefed account.
Thanks!
Thank you!
