CVE-2023-52139
Last modified
CVE-2023-52139 is a critical-severity vulnerability rated 9.6/10 on the CVSS scale. Misskey is an open source, decentralized social media platform. Third-party applications may be able to access some endpoints or Websocket APIs that are incorrectly specified as [kind](https://github.com/misskey-dev/misskey/blob/406b4bdbe79b5b0b68fcdcb3c4b6e419460a0258/packages/backend/src/server/api/endpoints.ts#L811) or [secure](https://github.com/misskey-dev/misskey/blob/406b4bdbe79b5b0b68fcdcb3c4b6e419460a0258/packages/backend/src/server/api/endpoints.ts#L805) without the user's permission and perform operations such as reading or adding non-public content. EPSS estimates a 0.55% chance of exploitation in the next 30 days.
Description
Misskey is an open source, decentralized social media platform. Third-party applications may be able to access some endpoints or Websocket APIs that are incorrectly specified as [kind](https://github.com/misskey-dev/misskey/blob/406b4bdbe79b5b0b68fcdcb3c4b6e419460a0258/packages/backend/src/server/api/endpoints.ts#L811) or [secure](https://github.com/misskey-dev/misskey/blob/406b4bdbe79b5b0b68fcdcb3c4b6e419460a0258/packages/backend/src/server/api/endpoints.ts#L805) without the user's permission and perform operations such as reading or adding non-public content. As a result, if the user who authenticated the application is an administrator, confidential information such as object storage secret keys and SMTP server passwords will be leaked, and general users can also create invitation codes without permission and leak non-public user information. This is patched in version [2023.12.1](https://github.com/misskey-dev/misskey/commit/c96bc36fedc804dc840ea791a9355d7df0748e64).
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Misskey | Misskey | < 2023.12.1 |
References
- https://github.com/misskey-dev/misskey/security/advisories/GHSA-7pxq-6xx9-xpgmThird Party Advisory
- https://github.com/misskey-dev/misskey/security/advisories/GHSA-7pxq-6xx9-xpgmThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-52139?
How severe is CVE-2023-52139?
How do I fix CVE-2023-52139?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-52133Improper Neutralization of Special Elements used in an SQL C…8.8
- CVE-2023-52134Improper Neutralization of Special Elements used in an SQL C…7.2
- CVE-2023-52135Improper Neutralization of Special Elements used in an SQL C…7.2
- CVE-2023-52136Cross-Site Request Forgery (CSRF) vulnerability in Smash Bal…8.8
- CVE-2023-52137The [`tj-actions/verify-changed-files`](https://github.com/t…8.8
- CVE-2023-52138Engrampa is an archive manager for the MATE environment. Eng…9.6
- CVE-2023-5214In Puppet Bolt versions prior to 3.27.4, a path to escalate …9.8
- CVE-2023-52140Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2023-52141Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2023-52142Improper Neutralization of Special Elements used in an SQL C…8.8
- CVE-2023-52143Exposure of Sensitive Information to an Unauthorized Actor v…7.5
- CVE-2023-52144Improper Limitation of a Pathname to a Restricted Directory …5.5
Are you affected by CVE-2023-52139?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
