PT-2022-16596 · Mastodon · Mastodon

·

CVE-2022-24307

·

Published

2022-02-03

·

Updated

2024-03-06

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mastodon versions 1.6.0 through 3.3.2 Mastodon versions 3.4.x through 3.4.5
Description The issue is related to incorrect access control due to the failure to compact incoming signed JSON-LD activities. JSON-LD signing has been supported since version 1.6.0.
Recommendations For Mastodon versions 1.6.0 through 3.3.2, update to version 3.3.2 or later. For Mastodon versions 3.4.x through 3.4.5, update to version 3.4.6 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-MASTODON-2022-24307
CVE-2022-24307

Affected Products

Mastodon