CVE-2024-52590
- EPSS 0.18%
- Veröffentlicht 18.12.2024 20:15:23
- Zuletzt bearbeitet 26.11.2025 15:48:13
Misskey is an open source, federated social media platform. In affected versions missing validation in `ApRequestService.signedGet` allows an attacker to create fake user profiles that appear to be from a different instance than the one where they ac...
CVE-2024-52593
- EPSS 0.28%
- Veröffentlicht 18.12.2024 20:15:23
- Zuletzt bearbeitet 26.11.2025 16:34:54
Misskey is an open source, federated social media platform.In affected versions missing validation in `NoteCreateService.insertNote`, `ApPersonService.createPerson`, and `ApPersonService.updatePerson` allows an attacker to control the target of any "...
CVE-2024-52592
- EPSS 0.37%
- Veröffentlicht 18.12.2024 20:15:23
- Zuletzt bearbeitet 26.11.2025 16:34:36
Misskey is an open source, federated social media platform. In affected versions missing validation in `ApInboxService.update` allows an attacker to modify the result of polls belonging to another user. No authentication is required, except for a val...
CVE-2024-52591
- EPSS 0.2%
- Veröffentlicht 18.12.2024 20:15:23
- Zuletzt bearbeitet 26.11.2025 16:25:19
Misskey is an open source, federated social media platform. In affected versions missing validation in `ApRequestService.signedGet` and `HttpRequestService.getActivityJson` allows an attacker to create fake user profiles and forged notes. The spoofed...
CVE-2024-52579
- EPSS 0.13%
- Veröffentlicht 18.12.2024 20:15:23
- Zuletzt bearbeitet 26.11.2025 16:33:39
Misskey is an open source, federated social media platform. Some APIs using `HttpRequestService` do not properly check the target host. This vulnerability allows an attacker to send POST or GET requests to the internal server, which may result in a S...
CVE-2024-32983
- EPSS 0.28%
- Veröffentlicht 03.06.2024 16:15:08
- Zuletzt bearbeitet 25.11.2025 20:37:04
Misskey is an open source, decentralized microblogging platform. Misskey doesn't perform proper normalization on the JSON structures of incoming signed ActivityPub activity objects before processing them, allowing threat actors to spoof the contents ...
CVE-2024-25636
- EPSS 0.21%
- Veröffentlicht 19.02.2024 20:15:46
- Zuletzt bearbeitet 05.02.2025 22:36:30
Misskey is an open source, decentralized social media platform with ActivityPub support. Prior to version 2024.2.0, when fetching remote Activity Streams objects, Misskey doesn't check that the response from the remote server has a `Content-Type` hea...
CVE-2023-52139
- EPSS 0.15%
- Veröffentlicht 29.12.2023 18:15:39
- Zuletzt bearbeitet 21.11.2024 08:39:15
Misskey is an open source, decentralized social media platform. Third-party applications may be able to access some endpoints or Websocket APIs that are incorrectly specified as [kind](https://github.com/misskey-dev/misskey/blob/406b4bdbe79b5b0b68fcd...
CVE-2023-49079
- EPSS 0.14%
- Veröffentlicht 29.11.2023 19:15:07
- Zuletzt bearbeitet 21.11.2024 08:32:46
Misskey is an open source, decentralized social media platform. Misskey's missing signature validation allows arbitrary users to impersonate any remote user. This issue has been patched in version 2023.11.1-beta.1.
CVE-2023-43793
- EPSS 0.21%
- Veröffentlicht 04.10.2023 21:15:10
- Zuletzt bearbeitet 21.11.2024 08:24:47
Misskey is an open source, decentralized social media platform. Prior to version 2023.9.0, by editing the URL, a user can bypass the authentication of the Bull dashboard, which is the job queue management UI, and access it. Version 2023.9.0 contains ...