Sourcehut account takeover via build logs (XSS in ansi2html)
发生了什么
A wormable vulnerability allowed anyone able to inject text in a build log on builds.sr.ht (or other instances) to take over accounts who viewed them
摘要按规则整理自下方来源原文
为什么在扩散
时间线
- Hacker News 最先出现Hacker News
- Lobsters 出现讨论Lobsters