blog! “An open(ish) redirect on Mastodon”
I've responsibly disclosed a small security issue with Mastodon (GHSA-8982-p7pm-7mqw). It allows a sufficiently determined attacker to use any Mastodon instance to redirect unwary users to a malicious site.
⸻
#ActivityPub #CyberSecurity #mastodon #ResponsibleDisclosure #security
Good news everybody!
This security issue has been fixed.
https://github.com/mastodon/mastodon/pull/27792
Attackers cannot use Mastodon as an open redirect any more.
@Edent
Is the link to GitHub broken, or is it just me? I get a 404 even if I'm logged in.
@Edent well, for @lapcatsoftware those news are very bad for his browser extension Homecoming...