CVE-2024-25108
Last modified
CVE-2024-25108 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Pixelfed is an open source photo sharing platform. When processing requests authorization was improperly and insufficiently checked, allowing attackers to access far more functionality than users intended, including to the administrative and moderator functionality of the Pixelfed server. EPSS estimates a 0.68% chance of exploitation in the next 30 days.
Description
Pixelfed is an open source photo sharing platform. When processing requests authorization was improperly and insufficiently checked, allowing attackers to access far more functionality than users intended, including to the administrative and moderator functionality of the Pixelfed server. This vulnerability affects every version of Pixelfed between v0.10.4 and v0.11.9, inclusive. A proof of concept of this vulnerability exists. This vulnerability affects every local user of a Pixelfed server, and can potentially affect the servers' ability to federate. Some user interaction is required to setup the conditions to be able to exercise the vulnerability, but the attacker could conduct this attack time-delayed manner, where user interaction is not actively required. This vulnerability has been addressed in version 0.11.11. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pixelfed | Pixelfed | >= 0.10.4, < 0.11.11 |
References
- https://github.com/pixelfed/pixelfed/security/advisories/GHSA-gccq-h3xj-jgvfExploit, Third Party Advisory
- https://github.com/pixelfed/pixelfed/security/advisories/GHSA-gccq-h3xj-jgvfExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-25108?
How severe is CVE-2024-25108?
How do I fix CVE-2024-25108?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-25100Deserialization of Untrusted Data vulnerability in WP Swings…9.8
- CVE-2024-25101Improper Neutralization of Input During Web Page Generation …4.8
- CVE-2024-25102This vulnerability exists in AppSamvid software due to the u…7.8
- CVE-2024-25103This vulnerability exists in AppSamvid software due to the u…6.3
- CVE-2024-25106OpenObserve is a observability platform built specifically f…6.5
- CVE-2024-25107WikiDiscover is an extension designed for use with a CreateW…6.1
- CVE-2024-25109ManageWiki is a MediaWiki extension allowing users to manage…5.4
- CVE-2024-2511Issue summary: Some non-default TLS server configurations ca…5.9
- CVE-2024-25110The UAMQP is a general purpose C library for AMQP 1.0. Durin…8.1
- CVE-2024-25111Squid is a web proxy cache. Starting in version 3.5.27 and p…7.5
- CVE-2024-25112Exiv2 is a command-line utility and C++ library for reading,…5
- CVE-2024-25113Rejected reason: This CVE was misassigned. See CVE-2023-4762…
Are you affected by CVE-2024-25108?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
