Skip to content

Piero Bosio Social Web Site Personale Logo Fediverso

Social Forum federato con il resto del mondo. Non contano le istanze, contano le persone

### Security Update: Hollo 0.6.19 Released

Fediverso
3 1 18
  • Security Update: Hollo 0.6.19 Released

    We have released Hollo 0.6.19 to address a security vulnerability in Fedify's HTML parsing code.

    This vulnerability (CVE-2025-68475) is a ReDoS (Regular Expression Denial of Service) issue that could allow an attacker to cause service unavailability by sending specially crafted HTML responses during federation operations. The malicious payload is small (approximately 170 bytes) but can block the Node.js event loop for extended periods.

    We strongly recommend all Hollo operators upgrade to version 0.6.19 immediately.

    Field Details
    CVE CVE-2025-68475
    Severity High (CVSS 7.5)
    Action Upgrade to Hollo 0.6.19

    #Hollo #Security #Fediverse #ActivityPub

  • 보안 업데이트: Hollo 0.6.19 릴리스

    Fedify의 HTML 파싱 코드에서 발견된 보안 취약점을 수정한 Hollo 0.6.19를 릴리스했습니다.

    이 취약점(CVE-2025-68475)은 ReDoS(정규 표현식 서비스 거부) 문제로, 공격자가 연합 작업 중 특수하게 조작된 HTML 응답을 보내 서비스 장애를 유발할 수 있습니다. 악성 페이로드는 작지만(약 170바이트), Node.js 이벤트 루프를 장시간 차단할 수 있습니다.

    모든 Hollo 운영자분들께 즉시 버전 0.6.19로 업그레이드하실 것을 강력히 권고드립니다.

    항목 상세
    CVE CVE-2025-68475
    심각도 높음 (CVSS 7.5)
    조치 Hollo 0.6.19로 업그레이드

    #Hollo #보안 #페디버스 #연합우주 #ActivityPub

  • 보안 업데이트: Hollo 0.6.19 릴리스

    Fedify의 HTML 파싱 코드에서 발견된 보안 취약점을 수정한 Hollo 0.6.19를 릴리스했습니다.

    이 취약점(CVE-2025-68475)은 ReDoS(정규 표현식 서비스 거부) 문제로, 공격자가 연합 작업 중 특수하게 조작된 HTML 응답을 보내 서비스 장애를 유발할 수 있습니다. 악성 페이로드는 작지만(약 170바이트), Node.js 이벤트 루프를 장시간 차단할 수 있습니다.

    모든 Hollo 운영자분들께 즉시 버전 0.6.19로 업그레이드하실 것을 강력히 권고드립니다.

    항목 상세
    CVE CVE-2025-68475
    심각도 높음 (CVSS 7.5)
    조치 Hollo 0.6.19로 업그레이드

    #Hollo #보안 #페디버스 #연합우주 #ActivityPub

    セキュリティアップデート: Hollo 0.6.19 リリース

    FedifyのHTMLパースコードにおけるセキュリティ脆弱性に対応したHollo 0.6.19をリリースしました。

    この脆弱性 (CVE-2025-68475) は ReDoS (正規表現によるサービス拒否) の問題であり、攻撃者がフェデレーション操作中に特別に細工されたHTMLレスポンスを送信することで、サービス停止を引き起こす可能性があります。悪意のあるペイロードは小さい (約170バイト) ですが、Node.jsのイベントループを長時間ブロックする可能性があります。

    すべてのHollo運営者の皆様には、直ちにバージョン 0.6.19 へのアップグレードを強くお勧めします。

    項目 詳細
    CVE CVE-2025-68475
    深刻度 高 (CVSS 7.5)
    対応 Hollo 0.6.19 にアップグレード

    #Hollo #セキュリティ #fediverse #ActivityPub

  • hongminhee@hollo.socialundefined hongminhee@hollo.social shared this topic on

Gli ultimi otto messaggi ricevuti dalla Federazione
Post suggeriti
  • 0 Votes
    1 Posts
    15 Views
    Just had dinner – Manchurian and Noodles. My brother’s exams got over today so a party of sorts. Tomorrow we have a ritual at home so wondering how it will all go as it will be fully packed and the meal prep has already started for tomorrow. By 3 pm I will be free. This morning felt a bit cold like again but not very much. Ugh! The weather! I hope it fades away quick whatever it is – the remaining. Tomorrow there are going to be ladies arriving for Pooja and then all family members to pray to goddess. I find all of the jazz so overwhelming and tiresome lord. I just want to rest and chillax. But obligations etc. Ugh! I hope strings of moments will pass through and I’ll be in Monday awaiting the November months weekend …Le sigh! I did my new moon journaling today. Late but did it. Tried to get off AI features on gmail etc and had lots of emails in my inbox stacked. Unsubscribed to tons! What the hell is going on with giant companies. Holy cow!
  • 0 Votes
    1 Posts
    12 Views
    Video: Lunchtime Timelapse 1-26-17Andy's Video Pub | original post: https://video.andyrush.net/video/lunchtime-timelapse-1-26-17/#ActivityPub #Fediverse #ReclaimOpen25 #unf
  • Fediverse blogging?

    Fediverso fediverse
    4
    0 Votes
    4 Posts
    31 Views
    Your blogging options with federation are: WordPress, Ghost, and WriteFreely
  • 0 Votes
    1 Posts
    6 Views
    Guest?
    EDIT - informationThis tutorial is supposed to be published by the tutorial profile of this server.It is designed to have several chapters, each being distinctively seperated by an own titel. In total as of now there are like besides this introduction like 6 chapters.posting and edition time of and by this EDIT profileof ver05 as of now 1hsmastodon review contact: @bitpickup--Categories:@helpers@forum.friendi.ca SPOILER - click to open/close || IntroductionThis tutorial is an adaption of the tutorial "creating a friendica server - ubuntu" by @hankg based on the experience of the installation report by @jesuisatirebitpickup:squeet.me/display/962c3e10-576…and specific help by @raroun.Server specs and friendica version used:VPS server | Ubuntu 22.04 LTSPHP Version 8.1.2-1ubuntu2.144 Core CPU, 8 GB Ram with 300GB NVME DiskFriendica [STABLE] | 'Giant Rhubarb' 2023.05 - 1518SPOILER - click to open/close || Installation environment and HowToThe only reasonable way to work with a VPSserver on the web is using the console.If you are not familiar with that don't worry, it is easy and the only thing you have to do is being able to copy/paste the commands displayed:¡Copy/paste only the codeBoxes like this one, located outside of the spoilers of this tutorial one after another without altering the sequence!Of course it is necessary to change the specific file names and passwords for you indiviual site, but that's all. promise!On the console you wont be able to copy/paste with the keyboard ctrl-C/ctrl-V technique, you'll have to use the mouse "right click, chose option" technique.This tutorial was created on a #debian #linux desktop environment.There shouldn't be differences if you want to do this from a #windows machine.The method used for communication between your local computer and the VPS server is called #SSH:Wikipedia - Secure Shell:"Cryptographic network protocol for secure data communication, remote shell services or command execution and other secure network services between two networked computers."#linux #debian #ubuntu #friendica #fediVerse #fediTutorial #tutorial #fediHelp #fediTips #activityPub #HowTo #DIY #VPS #server #selfHosting@admin@tupambae.org @tutorial@tupambae.org