this post was submitted on 10 Jul 2023
181 points (99.5% liked)

Feddit UK

1360 readers
1 users here now

Community for the Feddit UK instance.
A place to log issues, and for the admins to communicate with everyone.

founded 2 years ago
MODERATORS
 

So last night a XSS scripting attack was found on all Lemmy instances. See the lemmy world update here https://feddit.uk/post/453040

What this means is that hackers could inject their own "script" when any user viewed a comment/post that the hackers made. The hackers would then grab your JWT token with the script so they could impersonate that user. (And perform any actions on behalf of the user)

Luckily, it looks like I haven't been compromised so the site config should all be the same

What has been done about this

I've removed any comments or posts which included the script see here https://github.com/LemmyNet/lemmy-ui/issues/1895

I would have removed all custom emojis as well but there was none in our DB, this may potentially mean that this site was not affected. Just in case, I've also rotated the JWT tokens so all tokens are now invalid. This means you will have to logout and log back into the instance

Shoutout to @[email protected] for messaging me about this and bringing it to my attention

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 3 points 1 year ago (2 children)

Might not be related but after signing out I’ve not been able to sign back in to app.feddit.uk - using vger.app works fine though.

[–] [email protected] 3 points 1 year ago (1 children)

I think Tom.said that it breaks every time there's an update.

[–] [email protected] 2 points 1 year ago

I just saw his post about doing an update - it’s let me in now

[–] [email protected] 1 points 1 year ago

I've been able to sign into the generic wefwef webapp so unsure if there is a difference with the Feddit version.