CVE-2024-23832
Last modified
CVE-2024-23832 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Due to insufficient origin validation in all Mastodon, attackers can impersonate and take over any remote account. EPSS estimates a 1.93% chance of exploitation in the next 30 days.
Description
Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Due to insufficient origin validation in all Mastodon, attackers can impersonate and take over any remote account. Every Mastodon version prior to 3.5.17 is vulnerable, as well as 4.0.x versions prior to 4.0.13, 4.1.x version prior to 4.1.13, and 4.2.x versions prior to 4.2.5.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Joinmastodon | Mastodon | < 3.5.17 |
| Joinmastodon | Mastodon | >= 4.0.0, < 4.0.13 |
| Joinmastodon | Mastodon | >= 4.1.0, < 4.1.13 |
| Joinmastodon | Mastodon | >= 4.2.0, < 4.2.5 |
References
- http://www.openwall.com/lists/oss-security/2024/02/02/4Mailing List, Patch
- http://www.openwall.com/lists/oss-security/2024/02/02/4Mailing List, Patch
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-23832?
How severe is CVE-2024-23832?
How do I fix CVE-2024-23832?
Are you affected by CVE-2024-23832?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
