hhmx.de

Mastodon Engineering

Föderation EN Do 27.02.2025 17:42:10

We just released Mastodon 4.3.4, 4.2.17 and 4.1.23. They contain bug fixes as well as security fixes (medium severity)

We recommend every instance administrator to update as soon as possible.

If you are using our nightly releases, a container image with the fix has been published with the `nightly.2025-02-28-security` tag.

Full release notes and update instructions are available on our GitHub release page: github.com/mastodon/mastodon/r

Mastodon Engineering

Föderation EN Do 27.02.2025 17:43:04

If you are running Mastodon 4.2: Mastodon 4.2.17 drops support for Ruby 3.0 (which is no longer supported upstream).

If you are using Ruby 3.0, you can update to Mastodon 4.2.16 which contains the latest security fixes, but please note that this version has a known vulnerability if you are using SAML authentication with Mastodon.

If you are running Mastodon 4.2 + Ruby 3.0, we strongly encourage you to update to Ruby 3.2 and Mastodon 4.2.17 or above.

Mastodon Engineering

Föderation EN Do 27.02.2025 17:43:27

If you are running Mastodon 4.1, note that it only supports Ruby 3.0 (which is no longer supported upstream) and is subject to the above SAML security issue.

Mastodon 4.1 will no longer receive patches (including for security issues) after 2025-04-08 and we strongly encourage you to update to a newer Mastodon version.

Renaud Chaput

Föderation EN Do 27.02.2025 18:11:39

@mackuba Woops, thanks for noticing, fixed!