#securityfix — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #securityfix, aggregated by home.social.
-
🚨 Critical Composer Update: 2.9.8 & 2.2.28 fix a GitHub Actions token disclosure!
⚠️ Update NOW or disable GitHub Actions immediately!
#PHP #Composer #ComposerPHP #OpenSource #WebDevelopment #GitHubActions #DevSecOps #CyberSecurity #SoftwareUpdate #PatchRelease #DependencyManagement #SecurityFix #Programming #Packagist #PHPDev #ComposerUpdate #OpenSourceSoftware #WebDevLife #InfoSec #SecurityPatch #CodeSmart #DependencyManagement #SoftwareSecurity #TechUpdate
-
🚨 Critical Composer Update: 2.9.8 & 2.2.28 fix a GitHub Actions token disclosure!
⚠️ Update NOW or disable GitHub Actions immediately!
#PHP #Composer #ComposerPHP #OpenSource #WebDevelopment #GitHubActions #DevSecOps #CyberSecurity #SoftwareUpdate #PatchRelease #DependencyManagement #SecurityFix #Programming #Packagist #PHPDev #ComposerUpdate #OpenSourceSoftware #WebDevLife #InfoSec #SecurityPatch #CodeSmart #DependencyManagement #SoftwareSecurity #TechUpdate
-
🚨 Oh no, not another "all versions" #bug in FreeBSD! 🎉 Apparently, executing a program in your own system is now a privilege escalation 🧙♂️✨ Bravo to FreeBSD's stellar security team for fixing a problem that they didn't know existed until Ryan from Calif.io came along to enlighten them. 🙃🔒
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:13.exec.asc #FreeBSD #PrivilegeEscalation #SecurityFix #HackerNews #Califio #HackerNews #ngated -
🚨 Oh no, not another "all versions" #bug in FreeBSD! 🎉 Apparently, executing a program in your own system is now a privilege escalation 🧙♂️✨ Bravo to FreeBSD's stellar security team for fixing a problem that they didn't know existed until Ryan from Calif.io came along to enlighten them. 🙃🔒
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:13.exec.asc #FreeBSD #PrivilegeEscalation #SecurityFix #HackerNews #Califio #HackerNews #ngated -
Maston Update auf v4.3.6 erledigt.
#security #mastodon #admin #securityfix #update -
Samsung Galaxy S24 users in Europe, don’t miss the crucial February 2025 update! Key security fixes, performance improvements, Samsung-specific tweaks await. Ensure phone stays secure and smooth with just a quick update. #SamsungUpdate #GalaxyS24 #TechNews #SecurityFix
-
Samsung Galaxy S24 users in Europe, don’t miss the crucial February 2025 update! Key security fixes, performance improvements, Samsung-specific tweaks await. Ensure phone stays secure and smooth with just a quick update. #SamsungUpdate #GalaxyS24 #TechNews #SecurityFix
-
Mastodon benötigt ein Security-Update: **This release is an important security release fixing several security issue.**
sudo su mastodon
cd /home/mastodon/live
git fetch --tags
git checkout v4.2.10
bundle install
yarn install --frozen-lockfile
RAILS_ENV=production bundle exec rails assets:precompile
exit
sudo systemctl restart mastodon-sidekiq
sudo systemctl reload mastodon-web
sudo systemctl restart mastodon-streaming -
Mastodon benötigt ein Security-Update: **This release is an important security release fixing several security issue.**
sudo su mastodon
cd /home/mastodon/live
git fetch --tags
git checkout v4.2.10
bundle install
yarn install --frozen-lockfile
RAILS_ENV=production bundle exec rails assets:precompile
exit
sudo systemctl restart mastodon-sidekiq
sudo systemctl reload mastodon-web
sudo systemctl restart mastodon-streaming -
Der letzte Fix ist noch warm, da wird bereits der nächste nachgereicht.
**This release is an important security release fixing a major security issue.**
Folgende Schritte haben den Kuschelmammut von 4.2.6 auf 4.2.7 gehievt:
sudo su mastodon
cd /home/mastodon/live
git fetch --tags
git checkout v4.2.7
bundle install
yarn install --frozen-lockfile
RAILS_ENV=production bundle exec rails assets:precompile
exit
sudo systemctl restart mastodon-sidekiq
sudo systemctl reload mastodon-web
sudo systemctl restart mastodon-streamingWegen des MAJOR security issue sollte man das Update ziemlich dringend einspielen, denke ich.
-
⚠️ IMPORTANT SECURITY UPDATE ⚠️
Release 4.7.6 + 4.7.7More security fixes.
Changes:
- Security improvements
- Fixed bug preventing users from saving emails addresses or phone numbers
- Fixed profile picture export and import when exporting account
- Fixed bug that was causing duplicated profile pictures
- Now disallowing importing handle from exported profile
- Fixed syntax errors in Vietnamese translationFull changelog: https://github.com/LinkStackOrg/LinkStack/releases/tag/v4.7.6
-
⚠️ IMPORTANT SECURITY UPDATE ⚠️
Release 4.7.6 + 4.7.7More security fixes.
Changes:
- Security improvements
- Fixed bug preventing users from saving emails addresses or phone numbers
- Fixed profile picture export and import when exporting account
- Fixed bug that was causing duplicated profile pictures
- Now disallowing importing handle from exported profile
- Fixed syntax errors in Vietnamese translationFull changelog: https://github.com/LinkStackOrg/LinkStack/releases/tag/v4.7.6
-
Mastodon benötigt (schon wieder) ein Security-Update: **This release is an important security release fixing several security issue.**
Das Update von 4.2.5. auf 4.2.6. ist ziemlich trivial.
sudo su mastodon
cd /home/mastodon/live
git fetch --tags
git checkout v4.2.6
bundle install
yarn install --frozen-lockfile
RAILS_ENV=production bundle exec rails assets:precompile
exit
sudo systemctl restart mastodon-sidekiq
sudo systemctl reload mastodon-web
sudo systemctl restart mastodon-streaming -
⚠️ IMPORTANT SECURITY UPDATE ⚠️
Release 4.7.5We found another exploit, please update IMMEDIATELY.
Changes:
- Fixed JS Code Injection exploit
- Fixed Bluesky icon XML style information error #717
- Now resetting click count to zero when importing linksFull changelog: https://github.com/LinkStackOrg/LinkStack/releases/tag/v4.7.5
-
⚠️ IMPORTANT SECURITY UPDATE ⚠️
Release 4.7.5We found another exploit, please update IMMEDIATELY.
Changes:
- Fixed JS Code Injection exploit
- Fixed Bluesky icon XML style information error #717
- Now resetting click count to zero when importing linksFull changelog: https://github.com/LinkStackOrg/LinkStack/releases/tag/v4.7.5
-
Aus aktuellem Anlass: https://www.heise.de/news/Mastodon-Diebstahl-beliebiger-Identitaeten-im-foederierten-Kurznachrichtendienst-9615961.html
JEDER der eine Mastodon-Instanz betreibt sollte DRINGEND das aktuelle Update einspielen! JEDER!! JETZT!
Wer es aktuell nicht kann: Server runterfahren! Alles andere ist grob fahrlässig!
-
Heute muss ein dringendes Mastodon-Sicherheits-Update eingespielt werden.
Mastodon selbst meint dazu: **This release is an important security release fixing a critical security issue (CVE-2024-23832).**Die Schritte sind einfach:
sudo su mastodon
cd /home/mastodon/live
git fetch --tags
git checkout v4.2.5
bundle install
yarn install --frozen-lockfile
RAILS_ENV=production bundle exec rails assets:precompile
exit
sudo systemctl restart mastodon-sidekiq
sudo systemctl reload mastodon-web
sudo systemctl restart mastodon-streamingDanach meldet die Oberfläche das Update auf 4.2.5
Achtung: ich bin von 4.2.4 auf die neue Version gegangen. Ggf muss man, wenn man von einer früheren version installiert andere Schritte vornehmen!Vielen Dank an Hagen (@hbauer) Für die Info zum Update.
-
Wow!
Mastodon 4.2.5 GO! Podman, with Quadlet made it even EASIER than it was when I was just doing straight Podman with kubelet.Update version numbers in my def, systemctl restart mastodon-pod, boom. updated.
#mastoadmin #mastodon #securityfix #podman #quadlet #containers
-
Wow!
Mastodon 4.2.5 GO! Podman, with Quadlet made it even EASIER than it was when I was just doing straight Podman with kubelet.Update version numbers in my def, systemctl restart mastodon-pod, boom. updated.
#mastoadmin #mastodon #securityfix #podman #quadlet #containers
-
⚠️ IMPORTANT SECURITY FIX ⚠️
Release 4.2.3This update fixes a JS exploit using SVGs and removes metadata from images for improved privacy.
Please also boost this to spread awareness! :boost_requested:Changes:
- Fixed JS exploit using SVG
- Now sanitizing EXIF and metadata
- Now allowing multiple file types as profile picture
- Added new error messages
- New translation: Brazilian Portuguese 🇧🇷Full changelog: https://github.com/LinkStackOrg/LinkStack/releases/tag/v4.2.3
-
⚠️ IMPORTANT SECURITY FIX ⚠️
Release 4.2.3This update fixes a JS exploit using SVGs and removes metadata from images for improved privacy.
Please also boost this to spread awareness! :boost_requested:Changes:
- Fixed JS exploit using SVG
- Now sanitizing EXIF and metadata
- Now allowing multiple file types as profile picture
- Added new error messages
- New translation: Brazilian Portuguese 🇧🇷Full changelog: https://github.com/LinkStackOrg/LinkStack/releases/tag/v4.2.3
-
⚠️ IMPORTANT SECURITY FIX ⚠️
Release 4.1.2Prior to this version it was possible to execute malicious JavaScript code on LinkStack instances. PLEASE UPDATE IMMEDIATELY! ⚠️
Please also boost this to spread awareness! :boost_requested:
Changes:
- Fixed JavaScript injection exploit
- Fixed adding custom link favicon causing error 500Full changelog: https://github.com/LinkStackOrg/LinkStack/releases/tag/v4.1.2
-
⚠️ IMPORTANT SECURITY FIX ⚠️
Release 4.1.2Prior to this version it was possible to execute malicious JavaScript code on LinkStack instances. PLEASE UPDATE IMMEDIATELY! ⚠️
Please also boost this to spread awareness! :boost_requested:
Changes:
- Fixed JavaScript injection exploit
- Fixed adding custom link favicon causing error 500Full changelog: https://github.com/LinkStackOrg/LinkStack/releases/tag/v4.1.2
-
Heute zwischen 15 und 17 Uhr (13:00 UTC and 15:00 UTC) wird ein Security-Update für #Mastodon veröffentlicht. Alle #MastoAdmin|s sollten ihre Instanzen sofort aktualisieren. 🔥
A security update for #Mastodon will be released today between 3 and 5 p.m. (13:00 UTC and 15:00 UTC) All #MastoAdmin|s should update their instances immediately. 🔥
-
OpenSSH 9.2 Release Fixes 3 Security Issues
https://www.linuxtoday.com/developer/openssh-9-2-release/
#Securityfix #OpenSSH9.2 #Developer #release #bugfix #News -
Angular security fix concerning bindings of iframe elements is about to be released (breaking change): https://github.com/angular/angular/pull/48029
See also the corresponding error page in the Angular docs: https://angular.io/errors/NG0910
-
Angular security fix concerning bindings of iframe elements is about to be released (breaking change): https://github.com/angular/angular/pull/48029
See also the corresponding error page in the Angular docs: https://angular.io/errors/NG0910