minus-squarenon_burglar@lemmy.worldtoSelfhosted@lemmy.world•Umami is vulnerable - upgrade immediatelylinkfedilinkEnglisharrow-up1·edit-23 days agoThanks. For severe incidents like this, please post the most appropriate link, in this case https://github.com/umami-software/umami/issues/3852 Admins in self hosted usually don’t have that much experience with real, active compromise and may panic, let’s help them as much as possible. I will add that Umami itself is not compromised, but vulnerable. That is a somewhat misleading title. What was the vector? Did you have umami exposed publicly? linkfedilink
minus-squarenon_burglar@lemmy.worldtoSelfhosted@lemmy.world•Umami is vulnerable - upgrade immediatelylinkfedilinkEnglisharrow-up0·3 days agoLink? Did you discover this yourself? There is no actual info here. linkfedilink
minus-squarenon_burglar@lemmy.worldtoSelfhosted@lemmy.world•Decreasing Certificate Lifetimes to 45 DayslinkfedilinkEnglisharrow-up1·10 days agoAre you not using LE certbot to handle renewals? I can’t even imagine doing this manually. linkfedilink
Thanks.
For severe incidents like this, please post the most appropriate link, in this case https://github.com/umami-software/umami/issues/3852
Admins in self hosted usually don’t have that much experience with real, active compromise and may panic, let’s help them as much as possible.
I will add that Umami itself is not compromised, but vulnerable. That is a somewhat misleading title.
What was the vector? Did you have umami exposed publicly?