CVE-2024-49363
Last modified
CVE-2024-49363 is a high-severity vulnerability rated 7.4/10 on the CVSS scale. Misskey is an open source, federated social media platform. In affected versions FileServerService (media proxy) in github.com/misskey-dev/misskey 2024.10.1 or earlier did not detect proxy loops, which allows remote actors to execute a self-propagating reflected/amplified distributed denial-of-service via a maliciously crafted note. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
Misskey is an open source, federated social media platform. In affected versions FileServerService (media proxy) in github.com/misskey-dev/misskey 2024.10.1 or earlier did not detect proxy loops, which allows remote actors to execute a self-propagating reflected/amplified distributed denial-of-service via a maliciously crafted note. FileServerService.prototype.proxyHandler did not check incoming requests are not coming from another proxy server. An attacker can execute an amplified denial-of-service by sending a nested proxy request to the server and end the request with a malicious redirect back to another nested proxy request. Leading to unbounded recursion until the original request is timed out. This issue has been addressed in version 2024.11.0-alpha.3. Users are advised to upgrade. Users unable to upgrade may configure the reverse proxy to block requests to the proxy with an empty User-Agent header or one containing Misskey/. An attacker can not effectively modify the User-Agent header without making another request to the server.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-49363?
How severe is CVE-2024-49363?
How do I fix CVE-2024-49363?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-49358ZimaOS is a fork of CasaOS, an operating system for Zima dev…5.3
- CVE-2024-49359ZimaOS is a fork of CasaOS, an operating system for Zima dev…7.5
- CVE-2024-4936The Canto plugin for WordPress is vulnerable to Remote File …9.8
- CVE-2024-49360Sandboxie is a sandbox-based isolation software for 32-bit a…8.4
- CVE-2024-49361ACON is a widely-used library of tools for machine learning …8.1
- CVE-2024-49362Joplin is a free, open source note taking and to-do applicat…9.6
- CVE-2024-49364tiny-secp256k1 is a tiny secp256k1 native/JS wrapper. Prior …8.1
- CVE-2024-49365tiny-secp256k1 is a tiny secp256k1 native/JS wrapper. Prior …8.1
- CVE-2024-49366Nginx UI is a web user interface for the Nginx web server. N…7.5
- CVE-2024-49367Nginx UI is a web user interface for the Nginx web server. P…7.5
- CVE-2024-49368Nginx UI is a web user interface for the Nginx web server. P…9.8
- CVE-2024-49369Icinga is a monitoring system which checks the availability …9.8
Are you affected by CVE-2024-49363?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
