le_throosh@lemmy.dbzer0.com to Jellyfin: The Free Software Media System@lemmy.mlEnglish · 1 month agoCVE: Possible Organization/Secret Compromise from dangerous CI implementationwww.cvedetails.comexternal-linkmessage-square6linkfedilinkarrow-up129arrow-down10file-text
arrow-up129arrow-down1external-linkCVE: Possible Organization/Secret Compromise from dangerous CI implementationwww.cvedetails.comle_throosh@lemmy.dbzer0.com to Jellyfin: The Free Software Media System@lemmy.mlEnglish · 1 month agomessage-square6linkfedilinkfile-text
minus-squareLink@rentadrunk.orglinkfedilinkEnglisharrow-up8·1 month agoHasn’t it already been patched? https://github.com/jellyfin/jellyfin-ios/security/advisories/GHSA-7qhm-2m45-7fmh Patches CI workflows have been modified in all affected repositories, and secrets have been rotated. Furthermore, OPs post seems to link to the patch: https://github.com/jellyfin/jellyfin-ios/commit/109217e75f38394b2f6e46e25dfe5a721203d3c8
Hasn’t it already been patched? https://github.com/jellyfin/jellyfin-ios/security/advisories/GHSA-7qhm-2m45-7fmh
Furthermore, OPs post seems to link to the patch: https://github.com/jellyfin/jellyfin-ios/commit/109217e75f38394b2f6e46e25dfe5a721203d3c8