Vulnerabilities > CVE-2023-49095 - Unspecified vulnerability in Nexryai Nexkey 12.121.9/12.23Q4.4/12.23Q4.5
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
HIGH Availability impact
NONE Summary
nexkey is a microblogging platform. Insufficient validation of ActivityPub requests received in inbox could allow any user to impersonate another user in certain circumstances. This issue has been patched in version 12.122.2.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 4 |
References
- https://github.com/nexryai/nexkey/commit/b96da0eac5a1e75abba94cf926f1251842829bab
- https://github.com/nexryai/nexkey/commit/b96da0eac5a1e75abba94cf926f1251842829bab
- https://github.com/nexryai/nexkey/security/advisories/GHSA-fpxw-rw9v-2gmx
- https://github.com/nexryai/nexkey/security/advisories/GHSA-fpxw-rw9v-2gmx