Skip Navigation

Private message security issue for Lemmy 0.18.5

github.com

Any authenticated user may obtain private message details from other users on the same instance

Users can brute-force their way into reading private messages with Lemmy versions below 0.19.1. I know there was the question of federation issues previously, but it appears to have been largely mitigated with the later versions at this point. Are there any plans to upgrade pawb.social?

0 comments

No comments