CVE-2024-23832
Last modified
CVE-2024-23832 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Due to insufficient origin validation in all Mastodon, attackers can impersonate and take over any remote account. EPSS estimates a 1.93% chance of exploitation in the next 30 days.
Description
Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Due to insufficient origin validation in all Mastodon, attackers can impersonate and take over any remote account. Every Mastodon version prior to 3.5.17 is vulnerable, as well as 4.0.x versions prior to 4.0.13, 4.1.x version prior to 4.1.13, and 4.2.x versions prior to 4.2.5.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Joinmastodon | Mastodon | < 3.5.17 |
| Joinmastodon | Mastodon | >= 4.0.0, < 4.0.13 |
| Joinmastodon | Mastodon | >= 4.1.0, < 4.1.13 |
| Joinmastodon | Mastodon | >= 4.2.0, < 4.2.5 |
References
- http://www.openwall.com/lists/oss-security/2024/02/02/4Mailing List, Patch
- http://www.openwall.com/lists/oss-security/2024/02/02/4Mailing List, Patch
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-23832?
How severe is CVE-2024-23832?
How do I fix CVE-2024-23832?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-23827Nginx-UI is a web interface to manage Nginx configurations. …9.8
- CVE-2024-23828Nginx-UI is a web interface to manage Nginx configurations. …8.8
- CVE-2024-23829aiohttp is an asynchronous HTTP client/server framework for …6.5
- CVE-2024-2383A clickjacking vulnerability exists in zenml-io/zenml versio…6.1
- CVE-2024-23830MantisBT is an open source issue tracker. Prior to version 2…8.3
- CVE-2024-23831LedgerSMB is a free web-based double-entry accounting system…7.5
- CVE-2024-23833OpenRefine is a free, open source power tool for working wit…7.5
- CVE-2024-23834Discourse is an open-source discussion platform. Improperly …6.1
- CVE-2024-23835Suricata is a network Intrusion Detection System, Intrusion …7.5
- CVE-2024-23836Suricata is a network Intrusion Detection System, Intrusion …7.5
- CVE-2024-23837LibHTP is a security-aware parser for the HTTP protocol. Cra…7.5
- CVE-2024-23838TrueLayer.NET is the .Net client for TrueLayer. The vulnera…7.5
Are you affected by CVE-2024-23832?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
