Yes I re-read the cve, I thought it was an issue with an npm package with a cryptominer
Comment on Umami is compromised - upgrade immediately
GraveyardOrbit@lemmy.zip 4 days ago[deleted]
GottaHaveFaith@fedia.io 4 days ago
frongt@lemmy.zip 4 days ago
Unless it was the software package itself that was compromised.
EncryptKeeper@lemmy.world 3 days ago
It was not
EncryptKeeper@lemmy.world 4 days ago
Yeah but Umami is an analytics engine power by client side tracking. If it was behind a VPN it would be useless.