Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-25108

Опубликовано: 12 фев. 2024
Источник: nvd
CVSS3: 9.9
CVSS3: 8.8
EPSS Низкий

Описание

Pixelfed is an open source photo sharing platform. When processing requests authorization was improperly and insufficiently checked, allowing attackers to access far more functionality than users intended, including to the administrative and moderator functionality of the Pixelfed server. This vulnerability affects every version of Pixelfed between v0.10.4 and v0.11.9, inclusive. A proof of concept of this vulnerability exists. This vulnerability affects every local user of a Pixelfed server, and can potentially affect the servers' ability to federate. Some user interaction is required to setup the conditions to be able to exercise the vulnerability, but the attacker could conduct this attack time-delayed manner, where user interaction is not actively required. This vulnerability has been addressed in version 0.11.11. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:pixelfed:pixelfed:*:*:*:*:*:*:*:*
Версия от 0.10.4 (включая) до 0.11.11 (исключая)

EPSS

Процентиль: 25%
0.00084
Низкий

9.9 Critical

CVSS3

8.8 High

CVSS3

Дефекты

CWE-280
CWE-863

Связанные уязвимости

CVSS3: 9.9
github
почти 2 года назад

Pixelfed doesn't check OAuth Scopes in API routes, giving elevated permissions

CVSS3: 9.9
fstec
почти 2 года назад

Уязвимость реализации прикладного программного интерфейса платформы совместного использования изображений Pixelfed, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 25%
0.00084
Низкий

9.9 Critical

CVSS3

8.8 High

CVSS3

Дефекты

CWE-280
CWE-863