What is Nostr?
Ryan Baumann /
npub1jz6…wwpv
2024-03-23 20:32:34

Ryan Baumann on Nostr: I don't know who needs to hear this but #TruthSocial, which is running a forked ...

I don't know who needs to hear this but #TruthSocial, which is running a forked version of Mastodon, does not from the source code appear to have appropriate mitigations in place for CVE-2023-36460, which theoretically allows attackers to create and overwrite any file Mastodon has access to, allowing Denial of Service and arbitrary Remote Code Execution https://nvd.nist.gov/vuln/detail/CVE-2023-36460 (probably other CVE's as well, but some rely on federation which Truth Social doesn't use?) #infosec
Author Public Key
npub1jz68unhxf3e8c43c55h2fj2s9aal2cr5ptxp6nnedvc8zv5qd5rsrrwwpv