• RoundSparrow@lemmy.ml
    link
    fedilink
    English
    arrow-up
    2
    ·
    1 year ago

    The JWT are likely a hot issue, already some Issues on GitHub about them not being revoked properly.

    • CMahaff@lemmy.ml
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 year ago

      Oh man, that would be brutal if they are resetting the password and it isn’t kicking the attacker out…

      • Max-P@lemmy.max-p.me
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 year ago

        That’s probably what happened here because they did revoke the admin’s access, but it continued.