CRITICAL🇵🇱 Wersja polska

CVE-2024-23832

CVSS 9.4v3.1pub. 2024-02-01upd. 2024-11-21

Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Due to insufficient origin validation in all Mastodon, attackers can impersonate and take over any remote account. Every Mastodon version prior to 3.5.17 is vulnerable, as well as 4.0.x versions prior to 4.0.13, 4.1.x version prior to 4.1.13, and 4.2.x versions prior to 4.2.5.

🤖 AI Analysis
How it works

Mastodon does not sufficiently verify the source (origin) of incoming ActivityPub requests, which is a classic case of CWE-290 (Authentication Bypass by Spoofing). An attacker can craft malicious ActivityPub requests that impersonate activity originating from remote accounts on other instances. The lack of rigorous sender identity verification allows bypassing authentication mechanisms without any additional privileges or interaction from the victim.

Impact

An attacker can impersonate any remote user account and take full control of it, leading to violations of integrity and availability of accounts in the federated Mastodon network.

Mitigation & patch

Mastodon should be updated to version 3.5.17 or higher (for 3.x branch), 4.0.13 or higher (for 4.0.x branch), 4.1.13 or higher (for 4.1.x branch), or 4.2.5 or higher (for 4.2.x branch). Patch available in the Mastodon project GitHub repository (commit 1726085db5cd73dd30953da858f9887bcc90b958).

Who is affected

All Mastodon versions earlier than 3.5.17, versions 4.0.x before 4.0.13, versions 4.1.x before 4.1.13, and versions 4.2.x before 4.2.5.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
  • Joinmastodon Mastodon

    APP
    Joinmastodon
    < 3.5.174.0.0 – 4.0.13 (excl.)4.1.0 – 4.1.13 (excl.)4.2.0 – 4.2.5 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-36459CRITICAL9.3PL ✓same product

XSS w Mastodon poprzez spreparowane dane oEmbed w kartach podglądu

CVE-2023-36460CRITICAL9.9PL ✓same product

Mastodon: path traversal w przetwarzaniu mediów umożliwia RCE

CVE-2022-2166CRITICAL9.8PL ✓same product

Brak ograniczenia prób uwierzytelniania w Mastodon (przed 4.0.0)

CVE-2022-24307CRITICAL9.8PL ✓same product

Mastodon: nieprawidłowa kontrola dostępu przez brak kompaktowania JSON-LD

CVE-2018-21018CRITICAL9.8PL ✓same product

Mastodon: błędna obsługa timeout sesji — niewystarczające wygasanie sesji