@adiz It appears only pleroma+forks are affected. Not that there aren't other zerodays or attack vectors for the other softwares.
@james @dcc @adiz https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy
Headers that prevent media from behaving a certain way in the browser.
β turn this off, do the csp thing, 403 any .js .svg .exe .html .sh .askdfa;dka;sdfkjasldfj files
and then wait for pleroma to give an actual patch.
@splitshockvirus @theorytoe @dcc @james @adiz
Well, this one looks like a good enough guide: https://arachnid.town/objects/cb0605dd-fe69-4ec7-a6a3-9f9c2515f326
I still don't get why do I have to reconfigure Pleroma to use the subdomain to uploads and mediaproxy if I set up a redirect, but did that anyway π€·