Floofi Blog
Main website
  • Home
    • Welcome
    • 2025 progress report
    • 2024 progress report
      • Equestria.dev is now Floofi
  • Recent changes
    • Sunsetting Floofi Voice Generator
    • Taking a step back: 3 years later
    • Ditching GPG in favor of OpenSSH
    • Introducing Floofi Open Analytics
    • Announcing discontinuation of Faunerie
    • Removal of the status page API version 1 and "legacy" branches
    • Prisbeam is now Faunerie
    • Deprecation of the status page API version 1
    • Decomissioning DE1 and the notification server
    • Announcing merge between Equestria.dev Journal and Raindrops Blog
    • Improving reliability on our infrastructure
    • Removing translations on our website
    • Improving security for data at rest
    • Announcing deprecation of the Plural Connect services on May 18th
    • Giving Equestria.dev's applications an icon refresh
    • Discontinuation of Equestria.dev's DE1 datacenter
    • Improving Equestria.dev's transparency related to data hosting
    • Switching licenses for all open-source software from MIT to GNU AGPLv3
    • Equestria.dev's software plans for 2024
    • Taking a step back: 2 years later
    • Friendship truly is magic
    • Taking a step back: 1 year later
    • The end of the name "Minteck" (2018-2022)
    • Why did I give up on so many projects?
    • My thoughts on Reddit's r/place
    • Installing Alpine Linux and KDE Plasma
    • Taking a step back
    • This blog is finally back!
    • Giving up on Kartik
    • The future of Minteck Projects
    • How Windows 2000 was made
  • Security advisories
    • CVE-2024-12084 to -12088 and CVE-2024-12747 : rsync
    • CVE-2024-50573 and CVE-2024-49580
    • CVE-2024-6387 : OpenSSH Server
    • CVE-2024-2961 : GNU C Library
Powered by GitBook
On this page

Was this helpful?

  1. Security advisories

CVE-2024-50573 and CVE-2024-49580

Published: 2024-11-04

Last updated 6 months ago

Was this helpful?

Floofi is confirming that it has acknowledged the following vulnerabilities:

  • CVE-2024-50573, affecting JetBrains Hub ("Improper access control allowed users to generate permanent tokens for unauthorized services"); and

  • CVE-2024-49580, affecting Ktor ("Improper caching in HttpCache Plugin could lead to response information disclosure")

and confirms that it has minimal or no impact on Floofi's software and infrastructure.


The vulnerability with JetBrains Hub does affect id.floo.fi, but its impact is very minimal and only – at worst – increases attack surface on services connected to a Floofi ID. This means an update is not immediately required but will still be deployed at a later time.

The vulnerability with Ktor does not impact any of the features or modules that the Floofi Voice Generator backend is using.

We would like to thank you for your continued trust.


Source: , October 2024. Floofi Systems shall not be held responsible for any errors present within this information, including any potential damage caused to information systems due to an error in this information.

JetBrains Security Bulletin