PT-2026-2182 · Mastodon · Mastodon
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Mastodon versions 4.3 through 4.3.16
Mastodon versions 4.4 through 4.4.10
Mastodon versions 4.5 through 4.5.3
Description
Mastodon is a free, open-source social network server based on ActivityPub. A flaw exists in the code handling the download of lists of severed relationships for a particular event. This code does not verify the ownership of the list before returning the lost relationships. Consequently, any registered local user can access lists of lost followers and followed users resulting from any severance event, effectively enumerating severance events across the system. The leaked information does not include the name of the account that lost follows and followers.
Recommendations
Update Mastodon to version 4.3.17 or later.
Update Mastodon to version 4.4.11 or later.
Update Mastodon to version 4.5.4 or later.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Mastodon