So last night a XSS scripting attack was found on all Lemmy instances. See the lemmy world update here https://feddit.uk/post/453040
What this means is that hackers could inject their own "script" when any user viewed a comment/post that the hackers made. The hackers would then grab your JWT token with the script so they could impersonate that user. (And perform any actions on behalf of the user)
Luckily, it looks like I haven't been compromised so the site config should all be the same
I would have removed all custom emojis as well but there was none in our DB, this may potentially mean that this site was not affected. Just in case, I've also rotated the JWT tokens so all tokens are now invalid. This means you will have to logout and log back into the instance
Shoutout to @[email protected] for messaging me about this and bringing it to my attention
I don't know if it's related. Since today when I login to the Jerboa app then try to post or close/reopen the app my account for feddit.uk disappears from the app. I have to keep logging in.
Thanks for the tip. I just tried that, didn't work. So I then I deleted all data and that did! It meant I had to login to all my accounts again but it seems to be working.
Ty for acting, however I cannot seem to log in on Jerboa. It shows me all of my subscribed feeds but then won't let me comment. Closing and reopening the app logs me out again
You may need to clear the cache and data for Jerboa on your phone first, then log back in. I was having the same issue, but that seemed to fix it for me.
glad you managed to protect our instance before anything bad happened, good job 🥳 i was worried i'd wake up to a rather spicy looking front page lol. thanks for the hard work!