Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions blog/2025-04-08-payjo-in-redis-misconfiguration.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,11 @@ authors: nothingmuch
tags: [security]
---

Disclaimer: the author indicated redis and docker compose were a liability
before, helped with the incident response, mitigation and removal of these
liabilities afterwards, has never had any access to the payjo.in infrastructure
and is not responsible for the misconfiguration or misdiagnosis of this
specific vulnerability.

Due to a docker misconfiguration, the `payjo.in` directory server had an open
redis database, allowing unauthorized parties to observe exchanges between pairs
Expand Down