9.8

CVE-2024-23832

Mastodon Remote user impersonation and takeover

Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Due to insufficient origin validation in all Mastodon, attackers can impersonate and take over any remote account. Every Mastodon version prior to 3.5.17 is vulnerable, as well as 4.0.x versions prior to 4.0.13, 4.1.x version prior to 4.1.13, and 4.2.x versions prior to 4.2.5.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
JoinmastodonMastodon Version < 3.5.17
JoinmastodonMastodon Version >= 4.0.0 < 4.0.13
JoinmastodonMastodon Version >= 4.1.0 < 4.1.13
JoinmastodonMastodon Version >= 4.2.0 < 4.2.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.93% 0.774
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
security-advisories@github.com 9.4 3.9 5.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
CWE-290 Authentication Bypass by Spoofing

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

http://www.openwall.com/lists/oss-security/2024/02/02/4
Patch
Mailing List
https://github.com/mastodon/mastodon/commit/1726085db5cd73dd30953da858f9887bcc90b958
Patch
https://github.com/mastodon/mastodon/security/advisories/GHSA-3fjr-858r-92rw
Vendor Advisory