A spam technique has been discovered that consisted in creating an account with a malicious URL in the username and the email of the intended victim, so that the victim would receive a verification email with the malicious URL inside it. It was most often combined with control characters to make the malicious URL even more visible.
Thanks to Devin McGovern from the Cyber Security Operations Department at Hyatt who responsibly disclosed this issue to the team.
To deal with the issue:
- Creating new such accounts has been blocked; See MBS-12827.
- Existing such accounts, around 40,000, have been removed (since new verification emails could still be requested); See MBBE-68.
It doesn’t affect mirrors so there is no update for MusicBrainz Docker.
The git tag is v-2023-01-10-hotfixes.
Continue reading “MusicBrainz Server hotfix, 2023-01-10”