Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-25619

Опубликовано: 14 фев. 2024
Источник: nvd
CVSS3: 3.1
CVSS3: 4.3
EPSS Низкий

Описание

Mastodon is a free, open-source social network server based on ActivityPub. When an OAuth Application is destroyed, the streaming server wasn't being informed that the Access Tokens had also been destroyed, this could have posed security risks to users by allowing an application to continue listening to streaming after the application had been destroyed. Essentially this comes down to the fact that when Doorkeeper sets up the relationship between Applications and Access Tokens, it uses a dependent: delete_all configuration, which means the after_commit callback setup on AccessTokenExtension didn't actually fire, since delete_all doesn't trigger ActiveRecord callbacks. To mitigate, we need to add a before_destroy callback to ApplicationExtension which announces to streaming that all the Application's Access Tokens are being "killed". Impact should be negligible given the affected application had to be owned by the user. None the less this issue has been addressed in versions

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:joinmastodon:mastodon:*:*:*:*:*:*:*:*
Версия до 3.5.18 (исключая)
cpe:2.3:a:joinmastodon:mastodon:*:*:*:*:*:*:*:*
Версия от 4.0.0 (включая) до 4.0.14 (исключая)
cpe:2.3:a:joinmastodon:mastodon:*:*:*:*:*:*:*:*
Версия от 4.1.0 (включая) до 4.1.14 (исключая)
cpe:2.3:a:joinmastodon:mastodon:*:*:*:*:*:*:*:*
Версия от 4.2.0 (включая) до 4.2.6 (исключая)

EPSS

Процентиль: 58%
0.00362
Низкий

3.1 Low

CVSS3

4.3 Medium

CVSS3

Дефекты

CWE-613
CWE-613

Связанные уязвимости

CVSS3: 3.1
debian
почти 2 года назад

Mastodon is a free, open-source social network server based on Activit ...

CVSS3: 3.1
fstec
почти 2 года назад

Уязвимость веб-приложения для развёртывания распределённых социальных сетей Mastodon, связанная с неверным сроком действия сеанса, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 58%
0.00362
Низкий

3.1 Low

CVSS3

4.3 Medium

CVSS3

Дефекты

CWE-613
CWE-613