Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Due to insufficient origin validation in all Mastodon, attackers can impersonate and take over any remote account. Every Mastodon version prior to 3.5.17 is vulnerable, as well as 4.0.x versions prior to 4.0.13, 4.1.x version prior to 4.1.13, and 4.2.x versions prior to 4.2.5.
Mastodon does not sufficiently verify the source (origin) of incoming ActivityPub requests, which is a classic case of CWE-290 (Authentication Bypass by Spoofing). An attacker can craft malicious ActivityPub requests that impersonate activity originating from remote accounts on other instances. The lack of rigorous sender identity verification allows bypassing authentication mechanisms without any additional privileges or interaction from the victim.
An attacker can impersonate any remote user account and take full control of it, leading to violations of integrity and availability of accounts in the federated Mastodon network.
Mastodon should be updated to version 3.5.17 or higher (for 3.x branch), 4.0.13 or higher (for 4.0.x branch), 4.1.13 or higher (for 4.1.x branch), or 4.2.5 or higher (for 4.2.x branch). Patch available in the Mastodon project GitHub repository (commit 1726085db5cd73dd30953da858f9887bcc90b958).
All Mastodon versions earlier than 3.5.17, versions 4.0.x before 4.0.13, versions 4.1.x before 4.1.13, and versions 4.2.x before 4.2.5.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:HJoinmastodon Mastodon
APPJoinmastodon< 3.5.174.0.0 – 4.0.13 (excl.)4.1.0 – 4.1.13 (excl.)4.2.0 – 4.2.5 (excl.)
Related vulnerabilities
XSS w Mastodon poprzez spreparowane dane oEmbed w kartach podglądu
Mastodon: path traversal w przetwarzaniu mediów umożliwia RCE
Brak ograniczenia prób uwierzytelniania w Mastodon (przed 4.0.0)
Mastodon: nieprawidłowa kontrola dostępu przez brak kompaktowania JSON-LD
Mastodon: błędna obsługa timeout sesji — niewystarczające wygasanie sesji