lanodan,
@lanodan@queer.hacktivis.me avatar

Security Release 2.5.4

Fix XML External Entity (XXE) loading vulnerability allowing to fetch arbitrary files from the server's filesystem.

https://pleroma.social/announcements/2023/08/05/pleroma-security-release-2.5.4/

pomstan,
@pomstan@xn--p1abe3d.xn--80asehdb avatar

@lanodan how this can be exploited?

lanodan, (edited )
@lanodan@queer.hacktivis.me avatar

@pomstan /api/v1/pleroma/remote_interaction (public) is a known way.

And I'm not a full-disclosure-on-day0 person so if you want exploit details it'll have to wait until I can be reasonably sure people have their software fixed.

feld,
@feld@bikeshed.party avatar

At least we are now in the same company as Postgres who also had this vulnerability in 2012 🥲

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3489

lanodan,
@lanodan@queer.hacktivis.me avatar

@feld >libxml2

Uuuh… let's say I'm glad I don't have untrusted/remote XML in my other software.

feld,
@feld@bikeshed.party avatar

Hello friends, I invite you to check this blog post that I found after receiving the report:

https://vuln.be/post/xxe-in-erlang-and-elixir/

Apparently the bundled Erlang XML library xmerl along with a few other Erlang/Elixir XML parsers are vulnerable by default and we had no clue.

shpuld,
@shpuld@shpposter.club avatar

@lanodan thanks for quick fixes

lanodan,
@lanodan@queer.hacktivis.me avatar

Also it was reported by @Mae so thanks a lot!

feld,
@feld@bikeshed.party avatar

Thank you for finding this Mae

every little fix makes us closer to being impenetrable 😇

  • All
  • Subscribed
  • Moderated
  • Favorites
  • fediverse
  • InstantRegret
  • magazineikmin
  • khanakhh
  • Youngstown
  • mdbf
  • Durango
  • slotface
  • GTA5RPClips
  • ngwrru68w68
  • rosin
  • kavyap
  • osvaldo12
  • thenastyranch
  • DreamBathrooms
  • tester
  • anitta
  • Leos
  • normalnudes
  • cubers
  • ethstaker
  • tacticalgear
  • everett
  • megavids
  • provamag3
  • modclub
  • cisconetworking
  • JUstTest
  • lostlight
  • All magazines