Описание
nexkey is a microblogging platform. Insufficient validation of ActivityPub requests received in inbox could allow any user to impersonate another user in certain circumstances. This issue has been patched in version 12.122.2.
Ссылки
- Patch
- PatchThird Party Advisory
- Patch
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 12.122.2 (исключая)
cpe:2.3:a:nexryai:nexkey:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 51%
0.00277
Низкий
8.6 High
CVSS3
7.5 High
CVSS3
Дефекты
CWE-20
EPSS
Процентиль: 51%
0.00277
Низкий
8.6 High
CVSS3
7.5 High
CVSS3
Дефекты
CWE-20