Global Feed Post Login
Replying to Avatar dog's best friend

The XML parser we're using is the most mature one in the ecosystem and comes with Erlang, but they apparently didn't care to disable this by default.

Avatar
Matt Hamilton [Maryland] 2y ago

nostr:npub1yck44z5zqxmwpqzqs75ay6ffjdw843ng9p6mz0lzfff3fgz2djlsngujmw nostr:npub108pv4cg5ag52nq082kd5leu9ffrn2gdg6g4xdwatn73y36uzplmq9uyev6 nostr:npub108zt8c43ulvdwnax2txurhhr07wdprl0msf608udz9rvpd5l68ascvdkr5 Yeah, in this case I wouldn't blame Pleroma devs entirely, what I said was mostly a joke.

Erlang/Elixir is a shit and immature language, so the fact that "the most mature [XML parser] in the ecosystem" is vulnerable to vulns from the early 2000's comes as no surprise to me.

Reply to this note

Please Login to reply.

Discussion

Avatar
:gnu:+bonifartius π’‚Όπ’„„ 2y ago

nostr:npub18994crjwnldrukwym5lz3y2nae84s84v20m2rkngtjnyg549lr6qvxmd6m nostr:npub1yck44z5zqxmwpqzqs75ay6ffjdw843ng9p6mz0lzfff3fgz2djlsngujmw nostr:npub108pv4cg5ag52nq082kd5leu9ffrn2gdg6g4xdwatn73y36uzplmq9uyev6 nostr:npub108zt8c43ulvdwnax2txurhhr07wdprl0msf608udz9rvpd5l68ascvdkr5

> erlang is shit and immature

*disappointed armstrong noises

Thread collapsed