Vulnerabilities > CVE-2024-23832 - Unspecified vulnerability in Joinmastodon Mastodon
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Due to insufficient origin validation in all Mastodon, attackers can impersonate and take over any remote account. Every Mastodon version prior to 3.5.17 is vulnerable, as well as 4.0.x versions prior to 4.0.13, 4.1.x version prior to 4.1.13, and 4.2.x versions prior to 4.2.5.
Vulnerable Configurations
Related news
References
- http://www.openwall.com/lists/oss-security/2024/02/02/4
- http://www.openwall.com/lists/oss-security/2024/02/02/4
- https://github.com/mastodon/mastodon/commit/1726085db5cd73dd30953da858f9887bcc90b958
- https://github.com/mastodon/mastodon/commit/1726085db5cd73dd30953da858f9887bcc90b958
- https://github.com/mastodon/mastodon/security/advisories/GHSA-3fjr-858r-92rw
- https://github.com/mastodon/mastodon/security/advisories/GHSA-3fjr-858r-92rw