Mastodon @Mastodon

We've discovered an issue in 2.3.2 that, in rare cases, allowed users to create accounts with the same username as existing accounts. If you have already upgraded to v2.3.2, it is recommended to upgrade to v2.3.3 as soon as possible.

v2.3.3 is a small patch and requires no extra steps, only getting the new code and restarting Mastodon.

A new rake task is included to troubleshoot/clean-up.

the "rare case" is that if you register an account, say "kaniini", somebody else can register "KaNiiNi" and it will allow it
honesty in security advisories is so 2005

@kaniini I think I managed to do a same-account-name registration bug with MediaWiki, like, a decade ago; you just appended an _ to the username and it let you assume that account without the _

(no idea if it got patched)

@Mastodon I don't have any tag for 2.3.3, is it normal ? As I don't update the code, I don't have the new rake take either ! Thx for help

@seb_vallee @Mastodon do: git fetch --tags

It will download the tag.

@Mastodon Is closing registrations a reasonable mitigation until the instance can get upgraded to 2.3.3?

@nolan @Mastodon assuming anyone you invite doesn't abuse the bug, yes