CVE-2024-25636
Last modified
CVE-2024-25636 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Misskey is an open source, decentralized social media platform with ActivityPub support. Prior to version 2024.2.0, when fetching remote Activity Streams objects, Misskey doesn't check that the response from the remote server has a `Content-Type` header value of the Activity Streams media type, which allows a threat actor to upload a crafted Activity Streams document to a remote server and make a Misskey instance fetch it, if the remote server accepts arbitrary user uploads. EPSS estimates a 0.66% chance of exploitation in the next 30 days.
Description
Misskey is an open source, decentralized social media platform with ActivityPub support. Prior to version 2024.2.0, when fetching remote Activity Streams objects, Misskey doesn't check that the response from the remote server has a `Content-Type` header value of the Activity Streams media type, which allows a threat actor to upload a crafted Activity Streams document to a remote server and make a Misskey instance fetch it, if the remote server accepts arbitrary user uploads. The vulnerability allows a threat actor to impersonate and take over an account on a remote server that satisfies all of the following properties: allows the threat actor to register an account; accepts arbitrary user-uploaded documents and places them on the same domain as legitimate Activity Streams actors; and serves user-uploaded document in response to requests with an `Accept` header value of the Activity Streams media type. Version 2024.2.0 contains a patch for the issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Misskey | Misskey | < 2024.2.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-25636?
How severe is CVE-2024-25636?
How do I fix CVE-2024-25636?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-25630Cilium is a networking, observability, and security solution…5.3
- CVE-2024-25631Cilium is a networking, observability, and security solution…5.3
- CVE-2024-25632eLabFTW is an open source electronic lab notebook for resear…8.8
- CVE-2024-25633eLabFTW is an open source electronic lab notebook for resear…5.4
- CVE-2024-25634alf.io is an open source ticket reservation system. Prior to…6.5
- CVE-2024-25635alf.io is an open source ticket reservation system. Prior to…8.8
- CVE-2024-25637October is a self-hosted CMS platform based on the Laravel P…5.4
- CVE-2024-25638dnsjava is an implementation of DNS in Java. Records in DNS …8.9
- CVE-2024-25639Khoj is an application that creates personal AI agents. The …7.5
- CVE-2024-2564A vulnerability was found in PandaXGO PandaX up to 20240310 …7.3
- CVE-2024-25640Iris is a web collaborative platform that helps incident res…5.4
- CVE-2024-25641Cacti provides an operational monitoring and fault managemen…7.2
Are you affected by CVE-2024-25636?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
