Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-25623

Опубликовано: 19 фев. 2024
Источник: nvd
CVSS3: 8.5
CVSS3: 7.7
EPSS Низкий

Описание

Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.2.7, 4.1.15, 4.0.15, and 3.5.19, when fetching remote statuses, Mastodon doesn't check that the response from the remote server has a Content-Type header value of the Activity Streams media type, which allows a threat actor to upload a crafted Activity Streams document to a remote server and make a Mastodon server fetch it, if the remote server accepts arbitrary user uploads. The vulnerability allows a threat actor to impersonate an account on a remote server that satisfies all of the following properties: allows the attacker to register an account; accepts arbitrary user-uploaded documents and places them on the same domain as the ActivityPub actors; and serves user-uploaded document in response to requests with an Accept header value of the Activity Streams media type. Versions 4.2.7, 4.1.15, 4.0.15, and 3.5.19 contain a fix for this issue.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:joinmastodon:mastodon:*:*:*:*:*:*:*:*
Версия до 3.5.19 (исключая)
cpe:2.3:a:joinmastodon:mastodon:*:*:*:*:*:*:*:*
Версия от 4.0.0 (включая) до 4.0.15 (исключая)
cpe:2.3:a:joinmastodon:mastodon:*:*:*:*:*:*:*:*
Версия от 4.1.0 (включая) до 4.1.15 (исключая)
cpe:2.3:a:joinmastodon:mastodon:*:*:*:*:*:*:*:*
Версия от 4.2.0 (включая) до 4.2.7 (исключая)

EPSS

Процентиль: 38%
0.00168
Низкий

8.5 High

CVSS3

7.7 High

CVSS3

Дефекты

CWE-434
CWE-434

Связанные уязвимости

CVSS3: 8.5
debian
почти 2 года назад

Mastodon is a free, open-source social network server based on Activit ...

EPSS

Процентиль: 38%
0.00168
Низкий

8.5 High

CVSS3

7.7 High

CVSS3

Дефекты

CWE-434
CWE-434