Joinmastodon

Mastodon

41 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.07%
  • Veröffentlicht 03.10.2024 18:15:04
  • Zuletzt bearbeitet 06.05.2025 18:30:39

In Mastodon 4.1.6, API endpoint rate limiting can be bypassed by setting a crafted HTTP request header.

  • EPSS 0.85%
  • Veröffentlicht 05.07.2024 18:15:32
  • Zuletzt bearbeitet 24.06.2025 16:04:05

Mastodon is a self-hosted, federated microblogging platform. Starting in version 2.6.0 and prior to versions 4.1.18 and 4.2.10, by crafting specific activities, an attacker can extend the audience of a post they do not own to other Mastodon users on ...

  • EPSS 0.17%
  • Veröffentlicht 19.02.2024 16:15:51
  • Zuletzt bearbeitet 18.12.2024 22:39:17

Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.2.7, 4.1.15, 4.0.15, and 3.5.19, when fetching remote statuses, Mastodon doesn't check that the response from the remote server has a `Content-Type` heade...

  • EPSS 0.36%
  • Veröffentlicht 14.02.2024 21:15:08
  • Zuletzt bearbeitet 18.12.2024 22:22:01

Mastodon is a free, open-source social network server based on ActivityPub. When an OAuth Application is destroyed, the streaming server wasn't being informed that the Access Tokens had also been destroyed, this could have posed security risks to use...

Exploit
  • EPSS 0.38%
  • Veröffentlicht 14.02.2024 21:15:08
  • Zuletzt bearbeitet 18.12.2024 22:27:39

Mastodon is a free, open-source social network server based on ActivityPub. Mastodon allows new identities from configured authentication providers (CAS, SAML, OIDC) to attach to existing local users with the same e-mail address. This results in a po...

  • EPSS 1.76%
  • Veröffentlicht 01.02.2024 17:15:10
  • Zuletzt bearbeitet 21.11.2024 08:58:31

Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Due to insufficient origin validation in all Mastodon, attackers can impersonate and take over any remote account. Ev...

  • EPSS 0.78%
  • Veröffentlicht 19.09.2023 16:15:13
  • Zuletzt bearbeitet 21.11.2024 08:22:33

Mastodon is a free, open-source social network server based on ActivityPub. In versions on the 4.x branch prior to versions 4.0.10, 4.2.8, and 4.2.0-rc2, under certain conditions, attackers can abuse the translation feature to bypass the server-side ...

  • EPSS 0.38%
  • Veröffentlicht 19.09.2023 16:15:13
  • Zuletzt bearbeitet 21.11.2024 08:22:33

Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 3.5.14, 4.0.10, 4.1.8, and 4.2.0-rc2, under certain circumstances, attackers can exploit a flaw in domain name normalization to spoof domains they do not ow...

  • EPSS 0.46%
  • Veröffentlicht 19.09.2023 16:15:12
  • Zuletzt bearbeitet 21.11.2024 08:22:33

Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 4.2.0-beta1 and prior to version 4.2.0-rc2, by crafting specific input, attackers can inject arbitrary data into HTTP requests issued by Mastodon. This ca...

  • EPSS 1.46%
  • Veröffentlicht 06.07.2023 20:15:09
  • Zuletzt bearbeitet 21.11.2024 08:09:45

Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 2.6.0 and prior to versions 3.5.9, 4.0.5, and 4.1.3, an attacker can craft a verified profile link using specific formatting to conceal arbitrary parts of...